CVE-2026-0286: PAN-OS: Authenticated Command Injection in CLI (Severity: MEDIUM)
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8Fixed in 12.1.7-h2Fixed in 12.1.4-h8Fixed in 11.2.13Fixed in 11.2.10-h11Fixed in 11.2.7-h18Fixed in 11.2.4-h20Fixed in 11.1.16Fixed in 11.1.13-h9Fixed in 11.1.10-h30Fixed in 11.1.7-h8Fixed in 11.1.6-h35Fixed in 11.1.4-h35Fixed in 10.2.18-h8Fixed in 10.2.16-h9Fixed in 10.2.13-h23Fixed in 10.2.10-h39Fixed in 10.2.7-h36 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.7-h36 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.13-h23 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.16-h9 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.10-h39 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.4-h35 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.13-h9 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.6-h35 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.7-h8 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.10-h30 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.4-h20 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.7-h18 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.10-h11 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.4-h8 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.18-h8 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.13 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.8 - Configuration
Enable threat prevention on the inbound traffic to management services so PAN-OS can block this authenticated command injection attempt.
PAN-OS management interface / inbound traffic for management services Threat prevention on inbound traffic to management services = enabled - Configuration
Decrypt inbound traffic to the management interface so the firewall can inspect it (required for Threat ID 510036 to protect against this vulnerability).
PAN-OS SSL Decryption for management access SSL Decryption for management interface inbound traffic = enabled - Configuration
Replace the Certificate for Inbound Traffic Management.
PAN-OS certificate for Inbound Traffic Management Certificate = replaced - Configuration
Route incoming traffic for the MGT port through a DP (data plane) port (e.g., enable management profile on a DP interface for management access).
PAN-OS management access routing (MGT port) Route MGT port traffic via DP port with management profile = enabled - Configuration
If you have a Threat Prevention subscription, enable Threat ID 510036 (from Applications and Threats content version 9122-10145 and later) to get limited coverage against this vulnerability.
Applications and Threats content (Threat ID 510036) Threat ID 510036 enabled = enabled - Compensating control
Restrict CLI access to a limited group of administrators to significantly minimize the security risk posed by this issue.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0286?
The severity of CVE-2026-0286 is rated as high with a score of 8.5.
How do I fix CVE-2026-0286?
To fix CVE-2026-0286, restrict CLI access to a limited group of authenticated administrators.
What type of vulnerability is CVE-2026-0286?
CVE-2026-0286 is classified as a command injection vulnerability in the management plane of PAN-OS.
Who is affected by CVE-2026-0286?
Authenticated administrators using Palo Alto Networks PAN-OS software are affected by CVE-2026-0286.
What can an attacker do with CVE-2026-0286?
An attacker can execute arbitrary OS commands as root if they have authenticated access to the vulnerable system.