CVE-2026-0272: PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) (Severity: MEDIUM)
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Other sources
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h7Fixed in 12.1.5Fixed in 11.2.4-h18Fixed in 11.2.7-h16Fixed in 11.2.10-h9Fixed in 11.2.11Fixed in 11.1.4-h34Fixed in 11.1.6-h33Fixed in 11.1.7-h7Fixed in 11.1.10-h27Fixed in 11.1.13-h7Fixed in 11.1.14Fixed in 10.2.7-h35Fixed in 10.2.10-h37Fixed in 10.2.13-h22Fixed in 10.2.16-h8Fixed in 10.2.18-h5 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18-h5 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h22 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.16-h8 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h37 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.7-h35 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h34 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.6-h33 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.10-h27 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h18 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.11 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.7-h16 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.4-h7 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.5 - Compensating control
Restrict access to the firewall management interface so it is reachable only from trusted internal IP addresses (and restrict CLI/admin access to a limited group of administrators) per Palo Alto Networks administrative access best-practice deployment guidelines.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0272?
CVE-2026-0272 has a CVSS severity score of 8.5, classified as high.
How do I fix CVE-2026-0272?
To fix CVE-2026-0272, upgrade PAN-OS to versions 12.1.4-h7, 12.1.5, or later, and for version 11.2, upgrade to 11.2.10-h9 or later.
Who is affected by CVE-2026-0272?
CVE-2026-0272 affects authenticated administrators with access to the Command Line Interface (CLI) of Palo Alto Networks PAN-OS devices.
What type of vulnerability is CVE-2026-0272?
CVE-2026-0272 is a privilege escalation vulnerability that allows unauthorized actions to be performed with root privileges.
When was CVE-2026-0272 published?
CVE-2026-0272 was published on June 10, 2026.