CVE-2026-0308: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.10Fixed in 11.2.13-h2Fixed in 11.1.16-h2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16-h2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.13-h2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.10 - Configuration
Decrypt inbound traffic to the management interface so the firewall can inspect it.
Palo Alto Networks firewall/NGFW management traffic SSL/TLS decryption for inbound management interface = enabled - Configuration
Enable threat prevention on the inbound traffic to management services.
Palo Alto Networks firewall/NGFW management traffic Threat Prevention on inbound traffic to management services = enabled - Configuration
Replace the Certificate for Inbound Traffic Management.
Palo Alto Networks firewall/NGFW inbound traffic management certificate Certificate for Inbound Traffic Management = replace - Configuration
Route incoming traffic for the MGT port through a DP (decryption proxy) port, e.g., enable management profile on a DP interface for management access.
Palo Alto Networks firewall/NGFW management profile routing MGT port inbound traffic routing via DP port = routed through DP port - Compensating control
If you have a Threat Prevention subscription, enable Threat ID 510040 and 510041 from Applications and Threats content version 9145-10233 and later (requires SSL Decryption).
Event History
Frequently Asked Questions
Which deployments are affected and which are excluded?
The issue applies to PAN-OS on PA-Series and VM-Series firewalls, plus Panorama virtual and M-Series appliances. Cloud NGFW and Prisma Access are not affected.
What access does an attacker need to exploit this issue?
An attacker must be an authenticated administrator and must be able to use the web interface to store or execute a JavaScript payload.