CVE-2026-0273High· 7.2▾ MidnightPoC availableA command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.6 · likelihood 0.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
1.2% → 1.4%
1 GitHub repo
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
pan-os >= 10.2.0, < 10.2.7pan-os >= 10.2.8, < 10.2.10pan-os >= 10.2.11, < 10.2.13pan-os >= 10.2.14, < 10.2.16pan-os = 10.2.7pan-os = 10.2.10pan-os = 10.2.13pan-os = 10.2.16pan-os = 10.2.17pan-os = 10.2.18pan-os >= 11.1.0, < 11.1.4pan-os >= 11.1.8, < 11.1.10pan-os >= 11.1.11, < 11.1.13pan-os >= 11.1.14, < 11.1.16pan-os = 11.1.4pan-os = 11.1.5pan-os = 11.1.6pan-os = 11.1.7pan-os = 11.1.10pan-os = 11.1.13pan-os = 11.1.14pan-os >= 11.2.0, < 11.2.4pan-os >= 11.2.5, < 11.2.7pan-os >= 11.2.8, < 11.2.10pan-os = 11.2.4pan-os = 11.2.7pan-os = 11.2.10pan-os = 11.2.11pan-os >= 12.1.2, < 12.1.4pan-os >= 12.1.5, < 12.1.7pan-os = 12.1.4Upgrade past the affected range:
pan-os 12.1.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-9474High· 7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
CVE-2026-0286High· 7.2A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly m…
CVE-2019-1579High· 8.1Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…
CVE-2024-0012Critical· 9.8An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2024-51378Critical· 10.0getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…