Skip to content
CVE 2026 0308

CVE 2026 0308

security.paloaltonetworks.com September 10, 2026

CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Required Configuration for Exposure

No special configuration is required to be affected by this issue.

Severity: LOW, Suggested Urgency: MODERATE

The risk is highest when you allow access to the management interface from external IP addresses on the internet. LOW - CVSS-BT: 1.1 / CVSS-B: 4.8 ( CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber )

You can reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface. LOW - CVSS-BT: 0.4 / CVSS-B: 2.4 ( CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber )

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Weakness Type and Impact

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Version Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 12.2 No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-h2 or later. PAN-OS 11.1 11.1.0 through 11.1.16 Upgrade to 11.1.16-h2 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version. Prisma Access No action needed.

Workarounds and Mitigations

No known workarounds exist for this issue. Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability: Route incoming traffic for the MGT port through a DP port , e.g., enabling management profile on a DP interface for management access. Replace the Certificate for Inbound Traffic Management . Decrypt inbound traffic to the management interface so the firewall can inspect it . Enable threat prevention on the inbound traffic to management services. Please note that this Threat ID requires SSL Decryption.

Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability:

Route incoming traffic for the MGT port through a DP port , e.g., enabling management profile on a DP interface for management access.

Replace the Certificate for Inbound Traffic Management .

Decrypt inbound traffic to the management interface so the firewall can inspect it .

Enable threat prevention on the inbound traffic to management services.

Please note that this Threat ID requires SSL Decryption.

Frequently Asked Questions

Q. Why do Threat Prevention signatures provide limited coverage?

Limited coverage in Threat Prevention means that while known attack patterns can be identified using the current Threat ID, variations may exist that cannot currently be detected. If this CVE and Required Configuration for Exposure impact your environment, we recommend upgrading to an unaffected version.

Limited coverage in Threat Prevention means that while known attack patterns can be identified using the current Threat ID, variations may exist that cannot currently be detected. If this CVE and Required Configuration for Exposure impact your environment, we recommend upgrading to an unaffected version.

cpe:2.3:o:palo_alto_networks:pan-os:12.1.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.4:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.3:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:h1:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:-:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.12:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.11:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.10:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.7:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.4:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.3:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.1:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.0:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:h1:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:-:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.15:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.14:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.13:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.12:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.11:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.10:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.4:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.3:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.1:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.0:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)12.1.0 and up to (excluding)12.1.10

OR cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.13 and up to (excluding)11.2.13-h2

OR cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.16 and up to (excluding)11.1.16-h2

Extracted Entities

Companies (1)

CVEs (1)

Platforms (2)

Vulnerabilities (1)