Skip to content
Threat Feed
high threat

CVE-2026-0308 Stored XSS in PAN-OS Web Interface

A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows an authenticated administrator to execute arbitrary JavaScript within the context of the management interface.

What's new

  • 1. added coverage for PAN-OS (12.2 < 12.2.3) +9 products Sep 9, 18:58 via palo-alto-networks
  • 2. added coverage for PAN-OS (12.2 < 12.2.3) +4 products Sep 9, 18:58 via palo-alto-networks

CVE-2026-0308 is a stored cross-site scripting (XSS) vulnerability affecting Palo Alto Networks PAN-OS software. The vulnerability resides in the web-based management interface, enabling a malicious authenticated administrator to inject and store arbitrary JavaScript payloads. When other users access the affected web interface, the stored payload executes in their browser context. The vulnerability is applicable to PA-Series and VM-Series firewalls, as well as Panorama management appliances. Although the vulnerability requires high privileges (authenticated administrator access), it is accessible over the network. Palo Alto Networks has confirmed that no malicious exploitation has been observed in the wild. Customers are advised to upgrade to the specified patched versions to remediate the vulnerability, as no workarounds are currently available.

Impact

Successful exploitation of this vulnerability could allow an authenticated attacker to compromise the sessions of other administrators accessing the PAN-OS management interface. This may lead to unauthorized actions performed on behalf of legitimate administrators, potentially impacting the integrity of the firewall configuration or management operations. The severity is assessed as low by the vendor, and the vulnerability does not impact Cloud NGFW or Prisma Access.

Recommendation

  1. Upgrade all affected PA-Series, VM-Series, and Panorama appliances to the recommended fixed versions immediately:
  • For PAN-OS 12.1, upgrade to version 12.1.10 or later.
  • For PAN-OS 11.2, upgrade to version 11.2.13-h2 or later.
  • For PAN-OS 11.1, upgrade to version 11.1.16-h2 or later.
  1. Implement network segmentation by restricting management interface access to a dedicated jump box or trusted management subnet to limit exposure.
  2. If Threat Prevention is licensed, enable Threat ID 510040 and 510041 and ensure appropriate SSL decryption is configured for inbound management traffic to facilitate inspection.

Immediate actions

Upgrade PAN-OS to fixed versions listed in the recommendation section

IT Operations 72h

Mitigations

Restrict management interface access via ACLs or Jump Box

immediate IT Operations

CVE-2026-0308