CVE-2026-0308: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)

Published Sep 9, 2026
·
Updated

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Affected Software

4 affected componentsFixes available
PAN-OS
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<12.1.10, =12.1.0, <11.2.13-h2, =11.2.0, <11.1.16-h2, =11.1.0
12.1.1011.2.13-h211.1.16-h2
Palo Alto Networks Prisma Access

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 12.1.10Fixed in 11.2.13-h2Fixed in 11.1.16-h2
  2. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.16-h2
  3. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.13-h2
  4. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.10
  5. Configuration

    Decrypt inbound traffic to the management interface so the firewall can inspect it.

    Palo Alto Networks firewall/NGFW management traffic SSL/TLS decryption for inbound management interface = enabled
  6. Configuration

    Enable threat prevention on the inbound traffic to management services.

    Palo Alto Networks firewall/NGFW management traffic Threat Prevention on inbound traffic to management services = enabled
  7. Configuration

    Replace the Certificate for Inbound Traffic Management.

    Palo Alto Networks firewall/NGFW inbound traffic management certificate Certificate for Inbound Traffic Management = replace
  8. Configuration

    Route incoming traffic for the MGT port through a DP (decryption proxy) port, e.g., enable management profile on a DP interface for management access.

    Palo Alto Networks firewall/NGFW management profile routing MGT port inbound traffic routing via DP port = routed through DP port
  9. Compensating control

    If you have a Threat Prevention subscription, enable Threat ID 510040 and 510041 from Applications and Threats content version 9145-10233 and later (requires SSL Decryption).

Event History

Sep 9, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected and which are excluded?

The issue applies to PAN-OS on PA-Series and VM-Series firewalls, plus Panorama virtual and M-Series appliances. Cloud NGFW and Prisma Access are not affected.

2

What access does an attacker need to exploit this issue?

An attacker must be an authenticated administrator and must be able to use the web interface to store or execute a JavaScript payload.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203