CVE-2026-0256: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published May 13, 2026
·
Updated
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
Recommended actions to resolve this vulnerability, in priority order.
Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7Fixed in 12.1.4-h5Fixed in 11.2.12Fixed in 11.2.10-h6Fixed in 11.2.7-h13Fixed in 11.2.4-h17Fixed in 11.1.15Fixed in 11.1.13-h5Fixed in 11.1.10-h25Fixed in 11.1.7-h6Fixed in 11.1.6-h32Fixed in 11.1.4-h33Fixed in 10.2.18-h6Fixed in 10.2.16-h7Fixed in 10.2.13-h21Fixed in 10.2.10-h36Fixed in 10.2.7-h34
Upgrade
Upgrade PAN-OS 10.2 to a version that resolves this vulnerability.
Fixed in 10.2.18-h6
Upgrade
Upgrade PAN-OS 11.1 to a version that resolves this vulnerability.
Fixed in 11.1.15
Upgrade
Upgrade PAN-OS 11.2 to a version that resolves this vulnerability.
Fixed in 11.2.12
Upgrade
Upgrade PAN-OS 12.1 to a version that resolves this vulnerability.
Fixed in 12.1.7
Configuration
Replace the Certificate for Inbound Traffic Management used for inbound traffic to the management interface.
Certificate for Inbound Traffic Management Certificate = Replace with the updated certificate
Compensating control
If you have a Threat Prevention subscription, block this vulnerability by enabling Threat ID 510020 (from Applications and Threats content version 9100-10044 and later).
Compensating control
Enable threat prevention on the inbound traffic to management services.
Compensating control
Decrypt inbound traffic to the management interface so the firewall can inspect it.
Compensating control
Route incoming traffic for the MGT port through a DP port (e.g., enable management profile on a DP interface for management access).
The severity of CVE-2026-0256 is classified as MEDIUM.
2
What is the impact of CVE-2026-0256?
CVE-2026-0256 allows a malicious authenticated administrator to store a JavaScript payload, which may lead to Cross-Site Scripting (XSS) attacks.
3
How do I fix CVE-2026-0256?
To mitigate CVE-2026-0256, ensure you are using the latest version of PAN-OS or Panorama where the vulnerability is patched.
4
Who is affected by CVE-2026-0256?
CVE-2026-0256 affects users of Palo Alto Networks PAN-OS and Panorama applications.
5
What is a stored cross-site scripting vulnerability?
A stored cross-site scripting vulnerability is a security flaw that allows attackers to inject malicious scripts into web applications, impacting users who access the affected application.
SecAlerts Pty Ltd. 132 Wickham Terrace Fortitude Valley, QLD 4006, Australia info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.