CVE-2026-0308

PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Severity
Low 1.1
CVSS 4.0
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.003
16.8th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 10, 2026
Assigned by palo_alto

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Check your version Firewall / NGFW cna-assigner
Palo Alto Networks Panorama Network & Security Management description
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Michał Skowron and Tomasz Stachowicz of ING Hubs Poland and James Otten (internal reporter)

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW  No action needed.PAN-OS 12.2  No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-h2 or later. PAN-OS 11.1 11.1.0 through 11.1.16 Upgrade to 11.1.16-h2 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma AccessNo action needed.

Something wrong here?