CVE-2026-0261 Details
Description
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by these vulnerabilities.
Multiple command injection vulnerabilities have been identified in Palo Alto Networks PAN-OS software. These vulnerabilities allow an authenticated administrator to bypass system restrictions and execute arbitrary commands as a root user. The issues are present in PAN-OS versions 10.2, 11.1, 11.2, and 12.1, affecting PA-Series and VM-Series firewalls, as well as Panorama. However, Cloud NGFW and Prisma Access are not impacted. Exploitation requires access to the PAN-OS CLI or Web UI, and the risk is heightened when management interface access is allowed from external IP addresses.
Users can upgrade to the latest versions of PAN-OS 10.2, 11.1, 11.2, or 12.1. For specific upgrade instructions, refer to the Palo Alto Networks official documentation. Additionally, it's recommended to secure management interface access according to best practice guidelines, restricting access to trusted internal IP addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-967325.html | siemens-SADP | Third Party Advisory |
| https://security.paloaltonetworks.com/CVE-2026-0261 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks pan-os | < 10.2.7 >= 10.2.8, < 10.2.10 >= 10.2.11, < 10.2.13 >= 10.2.14, < 10.2.16 10.2.7 - 10.2.7 h1 10.2.7 h10 10.2.7 h11 10.2.7 h12 10.2.7 h13 10.2.7 h14 10.2.7 h15 10.2.7 h16 10.2.7 h17 10.2.7 h18 10.2.7 h19 10.2.7 h2 10.2.7 h20 10.2.7 h21 10.2.7 h22 10.2.7 h23 10.2.7 h24 10.2.7 h3 10.2.7 h32 10.2.7 h4 10.2.7 h5 10.2.7 h6 10.2.7 h7 10.2.7 h8 10.2.7 h9 10.2.10 - 10.2.10 h1 10.2.10 h10 10.2.10 h11 10.2.10 h12 10.2.10 h13 10.2.10 h14 10.2.10 h17 10.2.10 h18 10.2.10 h2 10.2.10 h21 10.2.10 h27 10.2.10 h3 10.2.10 h30 10.2.10 h31 10.2.10 h4 10.2.10 h5 10.2.10 h6 10.2.10 h7 10.2.10 h8 10.2.13 - 10.2.13 h1 10.2.13 h10 10.2.13 h15 10.2.13 h16 10.2.13 h18 10.2.13 h2 10.2.13 h3 10.2.13 h4 10.2.13 h5 10.2.13 h7 10.2.16 - 10.2.16 h1 10.2.16 h4 10.2.16 h6 10.2.17 - 10.2.18 - 10.2.18 h1 10.2.18 h5 >= 11.1.0, < 11.1.4 >= 11.1.5, < 11.1.6 >= 11.1.8, < 11.1.10 >= 11.1.11, < 11.1.13 11.1.4 - 11.1.4 h1 11.1.4 h10 11.1.4 h11 11.1.4 h12 11.1.4 h13 11.1.4 h15 11.1.4 h16 11.1.4 h17 11.1.4 h18 11.1.4 h2 11.1.4 h25 11.1.4 h27 11.1.4 h3 11.1.4 h32 11.1.4 h4 11.1.4 h5 11.1.4 h6 11.1.4 h7 11.1.4 h8 11.1.4 h9 11.1.6 - 11.1.6 h1 11.1.6 h10 11.1.6 h14 11.1.6 h17 11.1.6 h18 11.1.6 h19 11.1.6 h2 11.1.6 h20 11.1.6 h21 11.1.6 h22 11.1.6 h23 11.1.6 h25 11.1.6 h29 11.1.6 h3 11.1.6 h4 11.1.6 h5 11.1.6 h6 11.1.6 h7 11.1.7 - 11.1.7 h1 11.1.7 h2 11.1.7 h4 11.1.10 - 11.1.10 h1 11.1.10 h10 11.1.10 h12 11.1.10 h21 11.1.10 h4 11.1.10 h5 11.1.10 h7 11.1.10 h9 11.1.13 - 11.1.13 h1 11.1.13 h2 11.1.13 h3 11.1.14 - >= 11.2.0, < 11.2.4 >= 11.2.5, < 11.2.7 >= 11.2.8, < 11.2.10 11.2.4 - 11.2.4 h1 11.2.4 h10 11.2.4 h11 11.2.4 h12 11.2.4 h14 11.2.4 h15 11.2.4 h2 11.2.4 h3 11.2.4 h4 11.2.4 h5 11.2.4 h6 11.2.4 h7 11.2.4 h8 11.2.4 h9 11.2.7 - 11.2.7 h1 11.2.7 h10 11.2.7 h11 11.2.7 h12 11.2.7 h2 11.2.7 h3 11.2.7 h4 11.2.7 h7 11.2.7 h8 11.2.10 - 11.2.10 h1 11.2.10 h2 11.2.10 h3 11.2.10 h4 11.2.10 h5 11.2.11 - >= 12.1.0, < 12.1.4 >= 12.1.5, < 12.1.7 12.1.4 - 12.1.4 h2 12.1.4 h3 |
CPE
Remediation
| |
| siemens ruggedcom ape1808 firmware | All versions |
CPE
Remediation
| |
| siemens ruggedcom ape1808 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 9, 2026 | CVE Modified | siemens-SADP |
| May 13, 2026 | New CVE Received | [email protected] |