CVE-2026-0309: PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration (Severity: MEDIUM)
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM).
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.2.3Fixed in 12.1.10Fixed in 12.1.7-h5Fixed in 12.1.4-h10Fixed in 11.2.13-h2Fixed in 11.2.10-h14Fixed in 11.2.7-h20Fixed in 11.2.4-h21Fixed in 11.1.16-h2Fixed in 11.1.13-h12Fixed in 11.1.10-h33Fixed in 11.1.7-h10Fixed in 11.1.6-h38Fixed in 11.1.4-h36Fixed in 10.2.18-h10Fixed in 10.2.16-h10Fixed in 10.2.13-h24Fixed in 10.2.10-h40Fixed in 10.2.7-h37 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.7-h37 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h24 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.16-h10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18-h10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h40 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h36 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.13-h12 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.6-h38 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.7-h10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.10-h33 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h21 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.7-h20 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.10-h14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.13-h2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.4-h10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.7-h5 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.2.3 - Compensating control
Restrict PAN-OS CLI access to a limited group of administrators to significantly minimize the risk of this authenticated command injection vulnerability (requires authenticated CLI access and a device configured with a Luna Hardware Security Module (HSM)).
Event History
Frequently Asked Questions
Which deployments are exposed to exploitation?
Exposure requires a PAN-OS device configured with a Luna Hardware Security Module and CLI access for an authenticated administrator. Panorama, Cloud NGFW, and Prisma Access are not impacted.
What level of access does an attacker need?
An attacker must already be an authenticated administrator with access to the PAN-OS CLI. Successful exploitation allows bypassing system restrictions and execution of arbitrary commands as root.
What can reduce risk if remediation cannot be applied immediately?
Restrict PAN-OS CLI access to a limited group of administrators. This significantly minimizes the security risk described for this issue.