CVE-2026-0308

PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.003
18.7th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 10, 2026
Assigned by palo_alto

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Panorama Network & Security Management description
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Michał Skowron and Tomasz Stachowicz of ING Hubs Poland and James Otten (internal reporter)

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW  No action needed.PAN-OS 12.2  No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-h2 or later. PAN-OS 11.1 11.1.0 through 11.1.16 Upgrade to 11.1.16-h2 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma AccessNo action needed.

Something wrong here?