---
id: CVE-2026-0273
title: >-
  A command injection vulnerability in Palo Alto Networks PAN-OS® software
  enables an authenticated administrator to bypass system restrictions and run
  arbitrary commands as a root user
summary: >-
  A command injection vulnerability in Palo Alto Networks PAN-OS® software
  enables an authenticated administrator to bypass system restrictions and run
  arbitrary commands as a root user. To be able to exploit this issue, the user
  must have…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: paloaltonetworks
product: pan-os
affected:
  - 'pan-os >= 10.2.0, < 10.2.7'
  - 'pan-os >= 10.2.8, < 10.2.10'
  - 'pan-os >= 10.2.11, < 10.2.13'
  - 'pan-os >= 10.2.14, < 10.2.16'
  - pan-os = 10.2.7
  - pan-os = 10.2.10
  - pan-os = 10.2.13
  - pan-os = 10.2.16
  - pan-os = 10.2.17
  - pan-os = 10.2.18
  - 'pan-os >= 11.1.0, < 11.1.4'
  - 'pan-os >= 11.1.8, < 11.1.10'
  - 'pan-os >= 11.1.11, < 11.1.13'
  - 'pan-os >= 11.1.14, < 11.1.16'
  - pan-os = 11.1.4
  - pan-os = 11.1.5
  - pan-os = 11.1.6
  - pan-os = 11.1.7
  - pan-os = 11.1.10
  - pan-os = 11.1.13
  - pan-os = 11.1.14
  - 'pan-os >= 11.2.0, < 11.2.4'
  - 'pan-os >= 11.2.5, < 11.2.7'
  - 'pan-os >= 11.2.8, < 11.2.10'
  - pan-os = 11.2.4
  - pan-os = 11.2.7
  - pan-os = 11.2.10
  - pan-os = 11.2.11
  - 'pan-os >= 12.1.2, < 12.1.4'
  - 'pan-os >= 12.1.5, < 12.1.7'
  - pan-os = 12.1.4
patched:
  - pan-os 12.1.7
published: '2026-06-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0273'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0273'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
  - exploit-available
epss: 0.01339
epssPercentile: 0.70078
ingestedAt: '2026-07-11T13:13:24.619Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-0273'
  checkedAt: '2026-09-24T07:52:56.124Z'
exploitAvailable: true
---

## Overview

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

## Affected

- `pan-os >= 10.2.0, < 10.2.7`
- `pan-os >= 10.2.8, < 10.2.10`
- `pan-os >= 10.2.11, < 10.2.13`
- `pan-os >= 10.2.14, < 10.2.16`
- `pan-os = 10.2.7`
- `pan-os = 10.2.10`
- `pan-os = 10.2.13`
- `pan-os = 10.2.16`
- `pan-os = 10.2.17`
- `pan-os = 10.2.18`
- `pan-os >= 11.1.0, < 11.1.4`
- `pan-os >= 11.1.8, < 11.1.10`
- `pan-os >= 11.1.11, < 11.1.13`
- `pan-os >= 11.1.14, < 11.1.16`
- `pan-os = 11.1.4`
- `pan-os = 11.1.5`
- `pan-os = 11.1.6`
- `pan-os = 11.1.7`
- `pan-os = 11.1.10`
- `pan-os = 11.1.13`
- `pan-os = 11.1.14`
- `pan-os >= 11.2.0, < 11.2.4`
- `pan-os >= 11.2.5, < 11.2.7`
- `pan-os >= 11.2.8, < 11.2.10`
- `pan-os = 11.2.4`
- `pan-os = 11.2.7`
- `pan-os = 11.2.10`
- `pan-os = 11.2.11`
- `pan-os >= 12.1.2, < 12.1.4`
- `pan-os >= 12.1.5, < 12.1.7`
- `pan-os = 12.1.4`

## Remediation

Upgrade past the affected range:

- `pan-os 12.1.7`
