CVE-2026-0279: PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload.
The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW is not affected by this vulnerability.
Other sources
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload.
The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW is not affected by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8Fixed in 11.2.13Fixed in 11.1.16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.13 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.8 - Upgrade
Upgrade
Prisma Accessto a version that resolves this vulnerability.Fixed in 12.1.8 - Compensating control
Restrict access to the management interface and access to the User-ID™ Authentication Portal to only trusted internal IP addresses, following Palo Alto Networks administrative access best-practice deployment guidelines.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0279?
The severity of CVE-2026-0279 is rated as medium with a score of 5.3.
What types of vulnerabilities are described in CVE-2026-0279?
CVE-2026-0279 describes multiple cross-site scripting (XSS) vulnerabilities in Palo Alto Networks PAN-OS software.
Who can exploit the CVE-2026-0279 vulnerabilities?
A malicious unauthenticated user can exploit the vulnerabilities in CVE-2026-0279.
What impact do the vulnerabilities in CVE-2026-0279 have?
The vulnerabilities in CVE-2026-0279 enable an attacker to store or execute malicious JavaScript payloads.
How can organizations mitigate CVE-2026-0279?
Organizations can mitigate CVE-2026-0279 by applying the latest security updates and patches provided by Palo Alto Networks.