CVE-2026-0308
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Description
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Panorama | Network & Security Management | description |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (3)
- Palo Alto Networks · Cloud NGFW — vendor states not affected
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
Credit
Michał Skowron and Tomasz Stachowicz of ING Hubs Poland and James Otten (internal reporter)
Vendor remediation
Version Minor Version Suggested Solution Cloud NGFW No action needed.PAN-OS 12.2 No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-h2 or later. PAN-OS 11.1 11.1.0 through 11.1.16 Upgrade to 11.1.16-h2 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma AccessNo action needed.