CVE-2026-0273: PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI (Severity: MEDIUM)
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Other sources
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h7Fixed in 12.1.7Fixed in 11.2.4-h18Fixed in 11.2.7-h16Fixed in 11.2.10-h9Fixed in 11.2.12Fixed in 11.1.4-h34Fixed in 11.1.6-h33Fixed in 11.1.7-h7Fixed in 11.1.10-h27Fixed in 11.1.13-h7Fixed in 11.1.15Fixed in 10.2.7-h35Fixed in 10.2.10-h37Fixed in 10.2.13-h22Fixed in 10.2.16-h8Fixed in 10.2.18-h7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.7-h35 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.10-h37 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.13-h22 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.16-h8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.18-h7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.4-h34 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.7-h7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.10-h27 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.13-h7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.6-h33 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.4-h18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.10-h9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7 - Configuration
Enable Threat Prevention on the inbound traffic to management services.
Palo Alto Networks firewall management interface inbound traffic Threat Prevention (enable) = enabled - Compensating control
Secure access to the management interface per the best practice deployment guidelines: decrypt inbound traffic to the management interface so the firewall can inspect it.
- Compensating control
Replace the Certificate for Inbound Traffic Management.
- Compensating control
Route incoming traffic for the MGT port through a DP port (for example, enable the management profile on a DP interface for management access).
- Compensating control
Restrict management interface access to only trusted internal IP addresses; minimize CLI and management web exposure by limiting CLI access to a limited group of administrators and allowing management web access only from trusted internal IP addresses.
- Compensating control
If you have a Threat Prevention subscription, block attacks for this vulnerability by enabling Threat IDs 510028 and 510029 (from Applications and Threats content version 9112-10102 and later).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0273?
CVE-2026-0273 has a high severity score of 8.6 according to the CVSS 4.0 standards.
How do I fix CVE-2026-0273?
To fix CVE-2026-0273, upgrade your PAN-OS to appropriate patched versions as recommended by Palo Alto Networks.
What systems are affected by CVE-2026-0273?
CVE-2026-0273 affects Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access products.
What type of vulnerability is CVE-2026-0273?
CVE-2026-0273 is classified as an authenticated admin command injection vulnerability.
Can CVE-2026-0273 be exploited remotely?
CVE-2026-0273 requires authenticated access to the PAN-OS CLI or Web UI to be exploited.