Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.
The risk is highest when you allow access to the management interface from external IP addresses on the internet.
You can greatly reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface. This will ensure that attacks can succeed only if they obtain privileged access through those specified IP addresses.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
All (custom)
12.1.0 (custom) before 12.1.5
11.2.0 (custom) before 11.2.11
11.1.0 (custom) before 11.1.14
10.2.0 (custom)
All (custom)
Timeline
| 2026-06-10: | Initial publication. |
Credits
Palo Alto Networks thanks Rajnish Gupta (internal reporter), James Otten (internal reporter), and Jasper Westerman of REQON B.V. for discovering and reporting this issue.
References
security.paloaltonetworks.com/CVE-2026-0266