CVE-2026-0266: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.5Fixed in 11.2.11Fixed in 11.1.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.11 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0266?
The severity of CVE-2026-0266 is classified as medium with a CVSS score of 4.8.
How do I fix CVE-2026-0266?
To fix CVE-2026-0266, upgrade to the recommended versions of PAN-OS based on your current version.
What types of firewalls are affected by CVE-2026-0266?
CVE-2026-0266 affects PAN-OS software running on PA-Series and VM-Series firewalls and on Panorama.
What kind of vulnerability is CVE-2026-0266?
CVE-2026-0266 is a stored cross-site scripting (XSS) vulnerability.
Is there a workaround for CVE-2026-0266?
There are currently no known workarounds or mitigations for CVE-2026-0266.