CVE-2026-0309: PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration (Severity: MEDIUM)

Published Sep 9, 2026
·
Updated

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM).

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Affected Software

4 affected componentsFixes available
Palo Alto Networks PAN-OS
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<12.2.3, =12.2.0, <12.1.4-h10, =12.1.0, <11.2.4-h21, =11.2.0, <11.1.4-h36, =11.1.0, <10.2.7-h37, =10.2.0
12.2.312.1.1012.1.7-h512.1.4-h1011.2.13-h211.2.10-h1411.2.7-h2011.2.4-h2111.1.16-h211.1.13-h1211.1.10-h3311.1.7-h1011.1.6-h3811.1.4-h3610.2.18-h1010.2.16-h1010.2.13-h2410.2.10-h4010.2.7-h37
Palo Alto Networks Prisma Access

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 12.2.3Fixed in 12.1.10Fixed in 12.1.7-h5Fixed in 12.1.4-h10Fixed in 11.2.13-h2Fixed in 11.2.10-h14Fixed in 11.2.7-h20Fixed in 11.2.4-h21Fixed in 11.1.16-h2Fixed in 11.1.13-h12Fixed in 11.1.10-h33Fixed in 11.1.7-h10Fixed in 11.1.6-h38Fixed in 11.1.4-h36Fixed in 10.2.18-h10Fixed in 10.2.16-h10Fixed in 10.2.13-h24Fixed in 10.2.10-h40Fixed in 10.2.7-h37
  2. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.7-h37
  3. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.13-h24
  4. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.16-h10
  5. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.18-h10
  6. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.10-h40
  7. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.4-h36
  8. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.13-h12
  9. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.6-h38
  10. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.7-h10
  11. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.10-h33
  12. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.16
  13. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.4-h21
  14. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.7-h20
  15. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.10-h14
  16. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.13-h2
  17. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.4-h10
  18. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.7-h5
  19. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.10
  20. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.2.3
  21. Compensating control

    Restrict PAN-OS CLI access to a limited group of administrators to significantly minimize the risk of this authenticated command injection vulnerability (requires authenticated CLI access and a device configured with a Luna Hardware Security Module (HSM)).

Event History

Sep 9, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to exploitation?

Exposure requires a PAN-OS device configured with a Luna Hardware Security Module and CLI access for an authenticated administrator. Panorama, Cloud NGFW, and Prisma Access are not impacted.

2

What level of access does an attacker need?

An attacker must already be an authenticated administrator with access to the PAN-OS CLI. Successful exploitation allows bypassing system restrictions and execution of arbitrary commands as root.

3

What can reduce risk if remediation cannot be applied immediately?

Restrict PAN-OS CLI access to a limited group of administrators. This significantly minimizes the security risk described for this issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203