Back

MEDIUM

PAN-OS: Authenticated Command Injection in CLI

Published Jul 9, 2026

Description

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root.

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Affected products

Remediation

Vendor solution

Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 12.1

12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later.

12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later.

PAN-OS 11.2

11.2.11 through 11.2.12 Upgrade to 11.2.13 or later.

11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h11 or 11.2.13 or later.

11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later.

11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later.

PAN-OS 11.1

11.1.14 through 11.1.15 Upgrade to 11.1.16 or later.

11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later.

11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later.

11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later.

11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later.

11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later.

PAN-OS 10.2

10.2.17 through 10.2.18-h* Upgrade to 10.2.18-h8 or later.

10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h9 or later.

10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h23 or later.

10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h39 or later.

10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h36 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access 

No action needed.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Jul 9, 2026
Updated Aug 11, 2026
Reserved Nov 3, 2025
CISA Vulnrichment
Updated Jul 9, 2026
NVD
Status Modified
Modified Aug 11, 2026
Red Hat
Severity n/a
Public date n/a