Stored Cross-Site Scripting Vulnerability in Palo Alto Networks PAN-OS
CVE-2026-0308

0.4LOW

Key Information:

Vendor
CVE Published:
10 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-0308?

A stored cross-site scripting vulnerability has been identified in Palo Alto Networks PAN-OS software. This vulnerability allows an authenticated administrator to store and execute malicious JavaScript payloads via the web interface. The issue is pertinent to PAN-OS running on PA-Series and VM-Series firewalls, as well as on Panorama (including virtual and M-Series versions). It's crucial to note that Cloud NGFW and Prisma Access are not susceptible to this vulnerability. Ensuring timely updates and proper security measures can mitigate the risks associated with this issue.

Affected Version(s)

PAN-OS 12.1.0 < 12.1.10

PAN-OS 11.2.0 < 11.2.13-h2

PAN-OS 11.1.0 < 11.1.16-h2

References

CVSS V4

Score:
0.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Skowron and Tomasz Stachowicz of ING Hubs Poland and James Otten (internal reporter)
.