CVE-2026-0261: PAN-OS: Authenticated Admin Command Injection Vulnerability
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by these vulnerabilities.
Other sources
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by these vulnerabilities.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7Fixed in 12.1.4-h5Fixed in 11.2.12Fixed in 11.2.10-h6Fixed in 11.2.7-h13Fixed in 11.2.4-h17Fixed in 11.1.15Fixed in 11.1.13-h5Fixed in 11.1.10-h25Fixed in 11.1.7-h6Fixed in 11.1.6-h32Fixed in 11.1.4-h33Fixed in 10.2.18-h6Fixed in 10.2.16-h7Fixed in 10.2.13-h21Fixed in 10.2.10-h36Fixed in 10.2.7-h34 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.18-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.7 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 10.2 (authenticated admin command injection)to a version that resolves this vulnerability.Fixed in 10.2.18-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 11.1 (authenticated admin command injection)to a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 11.2 (authenticated admin command injection)to a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 12.1 (authenticated admin command injection)to a version that resolves this vulnerability.Fixed in 12.1.7 - Configuration
Replace the Certificate for Inbound Traffic Management for inbound traffic to the management interface as described in the referenced best-practices guidance.
Palo Alto Networks firewall management interface (inbound to MGT port) Replace the Certificate for Inbound Traffic Management = Replace/renew certificate - Configuration
Enable threat prevention for inbound traffic to the management services so the firewall can inspect that traffic.
Palo Alto Networks firewall Threat prevention on inbound traffic to management services = Enable - Configuration
Decrypt inbound traffic to the management interface so the firewall can inspect it.
Palo Alto Networks firewall Decrypt inbound traffic to the management interface = Enable decryption - Configuration
Route incoming traffic for the MGT port through a DP port (e.g., enable the management profile on a DP interface for management access), per the referenced best-practices guidance.
Palo Alto Networks firewall Route incoming management (MGT) port traffic through DP port = Route via DP port - Compensating control
Secure access to the management interface by restricting management access to trusted internal IP addresses (applies to PAN-OS on PA-Series/VM-Series and Panorama).
- Compensating control
For Threat Prevention subscription users: enable Threat IDs 510017, 510018 and 510024 to block this vulnerability; enable Threat IDs 510021, 510025 and 510026 to detect this vulnerability (Threats content version 9100-10044 and later).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0261?
The severity of CVE-2026-0261 is classified as MEDIUM.
How do I fix CVE-2026-0261?
To fix CVE-2026-0261, apply the latest patches and updates provided by Palo Alto Networks for PAN-OS.
Who is affected by CVE-2026-0261?
CVE-2026-0261 affects authenticated administrators using Palo Alto Networks PAN-OS software.
What type of vulnerability is CVE-2026-0261?
CVE-2026-0261 is an authenticated admin command injection vulnerability.
What can an attacker do with CVE-2026-0261?
An attacker can exploit CVE-2026-0261 to bypass system restrictions and execute arbitrary commands as a root user.