CVE-2026-0309

PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

Severity
Medium 4
CVSS 4.0
Exploited
Not listed
EPSS
0.004
38.3th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 10, 2026
Assigned by palo_alto

Description

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM). The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

François Rigault

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2.3 or later. PAN-OS 12.1 12.1.8 through 12.1.9 Upgrade to 12.1.10 or later. 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h5 or 12.1.10 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h10 or 12.1.10 or later. PAN-OS 11.2 11.2.11 through 11.2.13-h* Upgrade to 11.2.13-h2 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h14 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h20 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h21 or later. PAN-OS 11.1 11.1.14 through 11.1.16-h* Upgrade or 11.1.16-h2 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h12 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h33  or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h10 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h38 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h36 or later. PAN-OS 10.2 10.2.17 through 10.2.18-h* Upgrade to 10.2.18-h10 or later. 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h10 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h24 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h40 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h37 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access  No action needed.

Something wrong here?