CVE-2026-0309: PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration (Severity: MEDIUM)

Published Sep 9, 2026
·
Updated

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM).

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Affected Software

4 affected componentsFixes available
Palo Alto Networks PAN-OS
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<12.2.3, =12.2.0, <12.1.4-h10, =12.1.0, <11.2.4-h21, =11.2.0, <11.1.4-h36, =11.1.0, <10.2.7-h37, =10.2.0
12.2.312.1.1012.1.7-h512.1.4-h1011.2.13-h211.2.10-h1411.2.7-h2011.2.4-h2111.1.16-h211.1.13-h1211.1.10-h3311.1.7-h1011.1.6-h3811.1.4-h3610.2.18-h1010.2.16-h1010.2.13-h2410.2.10-h4010.2.7-h37
Palo Alto Networks Prisma Access

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 12.2.3Fixed in 12.1.10Fixed in 12.1.7-h5Fixed in 12.1.4-h10Fixed in 11.2.13-h2Fixed in 11.2.10-h14Fixed in 11.2.7-h20Fixed in 11.2.4-h21Fixed in 11.1.16-h2Fixed in 11.1.13-h12Fixed in 11.1.10-h33Fixed in 11.1.7-h10Fixed in 11.1.6-h38Fixed in 11.1.4-h36Fixed in 10.2.18-h10Fixed in 10.2.16-h10Fixed in 10.2.13-h24Fixed in 10.2.10-h40Fixed in 10.2.7-h37
  2. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.7-h37
  3. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.13-h24
  4. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.16-h10
  5. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.10-h40
  6. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.4-h36
  7. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.13-h12
  8. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.6-h38
  9. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.7-h10
  10. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.10-h33
  11. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.4-h21
  12. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.7-h20
  13. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.10-h14
  14. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.4-h10
  15. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.7-h5
  16. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.10
  17. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.2.3
  18. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.18-h10
  19. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.16-h2
  20. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.13-h2
  21. Compensating control

    Significantly minimize the security risk by restricting PAN-OS CLI access to a limited group of administrators (authenticated access is required, and exploitation also requires the device to be configured with a Luna Hardware Security Module (HSM)).

Event History

Sep 9, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 10, 2026
CVE Published
via MITRE·05:44 AM
Data Sourced
via MITRE·05:44 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to exploitation?

Exposure requires a PAN-OS device configured with a Luna Hardware Security Module and CLI access for an authenticated administrator. Panorama, Cloud NGFW, and Prisma Access are not impacted.

2

What level of access does an attacker need?

An attacker must already be an authenticated administrator with access to the PAN-OS CLI. Successful exploitation allows bypassing system restrictions and execution of arbitrary commands as root.

3

What can reduce risk if remediation cannot be applied immediately?

Restrict PAN-OS CLI access to a limited group of administrators. This significantly minimizes the security risk described for this issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203