---
id: CVE-2026-0308
title: >-
  A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks
  PAN-OS® software enables a malicious authenticated administrator to store or
  execute a JavaScript payload using the web interface
summary: >-
  A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks
  PAN-OS® software enables a malicious authenticated administrator to store or
  execute a JavaScript payload using the web interface. 


  This issue is applicable to PAN-…
severity: low
cvss: 1.1
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
cwe:
  - CWE-79
vendor: Palo Alto Networks
product: Cloud NGFW
affected:
  - cloud_ngfw
  - PAN-OS >= 12.1.0 < 12.1.10
  - PAN-OS >= 11.2.0 < 11.2.13-h2
  - PAN-OS >= 11.1.0 < 11.1.16-h2
  - prisma_access (all versions)
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T14:50:07.813'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0308'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0308'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T13:03:47.811775Z'
cvssSource: cna
ingestedAt: '2026-09-10T06:34:51.923Z'
epss: 0.00265
epssPercentile: 0.18712
---

## Overview

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. 

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). 

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
