CVE-2026-0273

Published Jun 10, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-0273 describes a command injection vulnerability found in Palo Alto Networks PAN-OS® software. This flaw permits an authenticated administrator to circumvent system restrictions and execute arbitrary commands with root privileges. The vulnerability impacts PAN-OS software on PA-Series and VM-Series firewalls, as well as Panorama (virtual and M-Series) appliances. To exploit this issue, an administrator must possess access to either the PAN-OS Command Line Interface (CLI) or the Web User Interface (Web UI). The security risk associated with this vulnerability is considerably mitigated when CLI access is restricted to a limited group of administrators and when access to the management web interface is confined to trusted internal IP addresses, adhering to recommended deployment guidelines. Cloud NGFW and Prisma® Access products are not affected by this vulnerability.

Description
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Source
psirt@paloaltonetworks.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Severity
MEDIUM

Weaknesses

psirt@paloaltonetworks.com
CWE-78

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

References

Sources include official advisories and independent security research.