---
id: CVE-2026-0279
title: >-
  Multiple cross site scripting vulnerabilities in the User-ID™ Authentication
  Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features
  and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious
  unauth…
summary: >-
  Multiple cross site scripting vulnerabilities in the User-ID™ Authentication
  Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features
  and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious
  unauth…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: paloaltonetworks
product: pan-os
affected:
  - 'pan-os >= 10.2.0, < 11.1.16'
  - 'pan-os >= 11.2.0, < 11.2.13'
  - 'pan-os >= 12.1.0, < 12.1.8'
patched:
  - pan-os 12.1.8
published: '2026-07-09'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0279'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0279'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.0075
epssPercentile: 0.53088
ingestedAt: '2026-07-13T13:27:18.262Z'
---

## Overview

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload.


The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW is not affected by this vulnerability.

## Affected

- `pan-os >= 10.2.0, < 11.1.16`
- `pan-os >= 11.2.0, < 11.2.13`
- `pan-os >= 12.1.0, < 12.1.8`

## Remediation

Upgrade past the affected range:

- `pan-os 12.1.8`
