{"id":"CVE-2026-0273","title":"A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user","summary":"A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"paloaltonetworks","product":"pan-os","affected":["pan-os >= 10.2.0, < 10.2.7","pan-os >= 10.2.8, < 10.2.10","pan-os >= 10.2.11, < 10.2.13","pan-os >= 10.2.14, < 10.2.16","pan-os = 10.2.7","pan-os = 10.2.10","pan-os = 10.2.13","pan-os = 10.2.16","pan-os = 10.2.17","pan-os = 10.2.18","pan-os >= 11.1.0, < 11.1.4","pan-os >= 11.1.8, < 11.1.10","pan-os >= 11.1.11, < 11.1.13","pan-os >= 11.1.14, < 11.1.16","pan-os = 11.1.4","pan-os = 11.1.5","pan-os = 11.1.6","pan-os = 11.1.7","pan-os = 11.1.10","pan-os = 11.1.13","pan-os = 11.1.14","pan-os >= 11.2.0, < 11.2.4","pan-os >= 11.2.5, < 11.2.7","pan-os >= 11.2.8, < 11.2.10","pan-os = 11.2.4","pan-os = 11.2.7","pan-os = 11.2.10","pan-os = 11.2.11","pan-os >= 12.1.2, < 12.1.4","pan-os >= 12.1.5, < 12.1.7","pan-os = 12.1.4"],"patched":["pan-os 12.1.7"],"published":"2026-06-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0273","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0273","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","exploit-available"],"epss":0.01339,"epssPercentile":0.69594,"ingestedAt":"2026-07-11T13:13:24.619Z","exploits":{"github":1,"githubRepos":["https://github.com/HORKimhab/CVE-2026-0273"],"checkedAt":"2026-09-21T15:27:49.367Z"},"exploitAvailable":true,"slug":"CVE-2026-0273","body":"## Overview\n\nA command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.\n\nThe security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\nThis issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).\n\nCloud NGFW and Prisma® Access are not affected by this vulnerability.\n\n## Affected\n\n- `pan-os >= 10.2.0, < 10.2.7`\n- `pan-os >= 10.2.8, < 10.2.10`\n- `pan-os >= 10.2.11, < 10.2.13`\n- `pan-os >= 10.2.14, < 10.2.16`\n- `pan-os = 10.2.7`\n- `pan-os = 10.2.10`\n- `pan-os = 10.2.13`\n- `pan-os = 10.2.16`\n- `pan-os = 10.2.17`\n- `pan-os = 10.2.18`\n- `pan-os >= 11.1.0, < 11.1.4`\n- `pan-os >= 11.1.8, < 11.1.10`\n- `pan-os >= 11.1.11, < 11.1.13`\n- `pan-os >= 11.1.14, < 11.1.16`\n- `pan-os = 11.1.4`\n- `pan-os = 11.1.5`\n- `pan-os = 11.1.6`\n- `pan-os = 11.1.7`\n- `pan-os = 11.1.10`\n- `pan-os = 11.1.13`\n- `pan-os = 11.1.14`\n- `pan-os >= 11.2.0, < 11.2.4`\n- `pan-os >= 11.2.5, < 11.2.7`\n- `pan-os >= 11.2.8, < 11.2.10`\n- `pan-os = 11.2.4`\n- `pan-os = 11.2.7`\n- `pan-os = 11.2.10`\n- `pan-os = 11.2.11`\n- `pan-os >= 12.1.2, < 12.1.4`\n- `pan-os >= 12.1.5, < 12.1.7`\n- `pan-os = 12.1.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `pan-os 12.1.7`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":39.6,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":4920,"id":"CVE-2026-0273","ts":1788887216134,"field":"exploit_available","old":"false","new":"true"},{"seq":3803,"id":"CVE-2026-0273","ts":1788886336994,"field":"exploit_available","old":"true","new":"false"},{"seq":2643,"id":"CVE-2026-0273","ts":1788883013898,"field":"exploit_available","old":"false","new":"true"},{"seq":1672,"id":"CVE-2026-0273","ts":1788882418129,"field":"exploit_available","old":"true","new":"false"},{"seq":780,"id":"CVE-2026-0273","ts":1788881851720,"field":"exploit_available","old":"false","new":"true"}]}