CVE-2026-0284

PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

Severity
Medium 4.7
CVSS 4.0
Exploited
Not listed
EPSS
0.005
39.5th percentile
Discovered by
Vendor
Vendor-published field
Published
Jul 9, 2026
Assigned by palo_alto

Description

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Weakness: CWE-74

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (4)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access — vendor states not affected
  • Siemens · RUGGEDCOM APE1808

Credit

our internal security research teams

Vendor remediation

VersionMinor Version RangeSuggested SolutionCloud NGFW No action needed.PAN-OS 12.112.1.5 through 12.1.7-h*Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h*Upgrade to 12.1.4-h8 or 12.1.8 or later.PAN-OS 11.211.2.11 through 11.2.12Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h*Upgrade to 11.2.10-h12 or 11.2.13 or later. 11.2.5 through 11.2.7-h*Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h*Upgrade to 11.2.4-h20 or 11.2.13 or later.PAN-OS 11.111.1.14 through 11.1.15Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h*Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h*Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h*Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h*Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h*Upgrade to 11.1.4-h35 or 11.1.16 or later.PAN-OS 10.210.2.17 through 10.2.18-h*Upgrade to 10.2.18-h8 or later. 10.2.14 through 10.2.16-h*Upgrade to 10.2.16-h9 or later. 10.2.11 through 10.2.13-h*Upgrade to 10.2.13-h23 or later. 10.2.8 through 10.2.10-h*Upgrade to 10.2.10-h39 or later. 10.2.0 through 10.2.7-h*Upgrade to 10.2.7-h36 or later.All other older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access No action needed.

Something wrong here?