{"id":"CVE-2026-0309","title":"PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration","summary":"A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…","severity":"medium","cvss":4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","cvssSource":"cna","cwe":["CWE-78"],"vendor":"Palo Alto Networks","product":"Cloud NGFW","affected":["cloud_ngfw","PAN-OS >= 12.2.0 < 12.2.3","PAN-OS >= 12.1.0 < 12.1.4-h10","PAN-OS >= 11.2.0 < 11.2.4-h21","PAN-OS >= 11.1.0 < 11.1.4-h36","PAN-OS >= 10.2.0 < 10.2.7-h37","prisma_access"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T00:00:00+00:00"},"published":"2026-09-10","updated":"2026-09-11","sourceUpdated":"2026-09-11T03:56:05.594Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-0309","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0309"}],"tags":["cve.org"],"epss":0.00447,"epssPercentile":0.38169,"ingestedAt":"2026-09-11T11:32:42.775Z","slug":"CVE-2026-0309","body":"## Overview\n\nA command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM). \n\nThe security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.\n\nPanorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.\n\n## Affected\n\n- `cloud_ngfw`\n- `PAN-OS >= 12.2.0 < 12.2.3`\n- `PAN-OS >= 12.1.0 < 12.1.4-h10`\n- `PAN-OS >= 11.2.0 < 11.2.4-h21`\n- `PAN-OS >= 11.1.0 < 11.1.4-h36`\n- `PAN-OS >= 10.2.0 < 10.2.7-h37`\n- `prisma_access`\n\n## Remediation\n\nVersion\nMinor Version\nSuggested Solution\nCloud NGFW No action needed.\n                                PAN-OS 12.2\n\n                                12.2.0 through 12.2.2\n                                Upgrade to 12.2.3 or later.\n                            \n                                PAN-OS 12.1\n\n                                12.1.8 through 12.1.9\n                                Upgrade to 12.1.10 or later.\n                            \n                                \n                                12.1.5 through 12.1.7-h*\n                                Upgrade to 12.1.7-h5 or 12.1.10 or later.\n                            \n                                \n                                12.1.2 through 12.1.4-h*\n                                Upgrade to 12.1.4-h10 or 12.1.10 or later.\n                            \n                                PAN-OS 11.2\n                                11.2.11 through 11.2.13-h*\n                                Upgrade to 11.2.13-h2 or later.\n                            \n                                \n                                11.2.8 through 11.2.10-h*\n                                Upgrade to 11.2.10-h14 or later.\n                            \n                                \n                                11.2.5 through 11.2.7-h*\n                                Upgrade to 11.2.7-h20 or later.\n                            \n                                \n                                11.2.0 through 11.2.4-h*\n                                Upgrade to 11.2.4-h21 or later.\n                            \n                                PAN-OS 11.1\n\n                                11.1.14 through 11.1.16-h*\n\n                                Upgrade or 11.1.16-h2 or later.\n                            \n                                \n                                11.1.11 through 11.1.13-h*\n                                Upgrade to 11.1.13-h12 or later.\n                            \n                                \n                                11.1.8 through 11.1.10-h*\n                                Upgrade to 11.1.10-h33  or later.\n                            \n                                \n                                11.1.7 through 11.1.7-h*\n                                Upgrade to 11.1.7-h10 or later.\n                            \n                                \n                                11.1.5 through 11.1.6-h*\n                                Upgrade to 11.1.6-h38 or later.\n                            \n                                \n                                11.1.0 through 11.1.4-h*\n                                Upgrade to 11.1.4-h36 or later.\n                            \n                                PAN-OS 10.2\n\n                                10.2.17 through \n10.2.18-h*\n                                Upgrade to 10.2.18-h10 or later.\n                            \n                                \n                                10.2.14 through 10.2.16-h*\n                                Upgrade to 10.2.16-h10 or later.\n                            \n                                \n                                10.2.11 through 10.2.13-h*\n                                Upgrade to 10.2.13-h24 or later.\n                            \n                                \n                                10.2.8 through 10.2.10-h*\n                                Upgrade to 10.2.10-h40 or later.\n                            \n                                \n                                10.2.0 through 10.2.7-h*\n                                Upgrade to 10.2.7-h37 or later.\n                            All older\nunsupported\nPAN-OS versions Upgrade to a supported fixed version.Prisma Access \nNo action needed.\n\n### Workarounds\n\nNo known workarounds exist for this issue.","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}