CVE-2026-0284: PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) (Severity: MEDIUM)
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h8Fixed in 12.1.7-h2Fixed in 12.1.8Fixed in 11.2.4-h20Fixed in 11.2.7-h18Fixed in 11.2.10-h12Fixed in 11.2.13Fixed in 11.1.4-h35Fixed in 11.1.6-h35Fixed in 11.1.7-h8Fixed in 11.1.10-h30Fixed in 11.1.13-h9Fixed in 11.1.16Fixed in 10.2.7-h36Fixed in 10.2.10-h39Fixed in 10.2.13-h23Fixed in 10.2.16-h9Fixed in 10.2.18-h8 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.7-h36 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.10-h39 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.13-h23 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.16-h9 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.4-h35 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.6-h35 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.7-h8 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.10-h30 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.13-h9 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.4-h20 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.7-h18 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.10-h12 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.4-h8 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.8 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.17 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.18-h8 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.13 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.7-h2 - Configuration
Enable Threat ID 510031 (Applications and Threats content version 9122-10145 and later) to obtain limited coverage against the PAN-OS XML Injection vulnerability in the Large Scale VPN (LSVPN) functionality.
Threat Prevention subscription Threat ID 510031 = enabled - Configuration
Ensure the vulnerability protection security profile is applied to your GlobalProtect interface so Threat ID 510031 provides effective protection.
Vulnerability protection security profile applied_to_globalprotect_interface = true
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0284?
The severity of CVE-2026-0284 is high with a score of 7.8.
How do I fix CVE-2026-0284?
To fix CVE-2026-0284, update your Palo Alto Networks PAN-OS to the latest version provided by the vendor.
What systems are affected by CVE-2026-0284?
CVE-2026-0284 affects Palo Alto Networks Cloud NGFW, PAN-OS, and Prisma Access software.
What type of vulnerability is CVE-2026-0284?
CVE-2026-0284 is an XML injection vulnerability specifically related to the Large Scale VPN functionality in PAN-OS.
What could happen if CVE-2026-0284 is exploited?
Exploitation of CVE-2026-0284 could lead to information disclosure or corruption of internal LSVPN satellite data.