CVE-2026-0286

Siemens ProductCERT Advisory SSA-104023

Description

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Metrics

Severity
high
no public PoC known
7.2
Source: nvd-v3
75.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.7 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-06-10 20:30 UTC
CWE-78

Weakness classes (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-11 13:17 UTC· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
    • Affected: RUGGEDCOM APE1808
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-104023.html

Affected operating systems

  • other

    paloaltonetworks / pan-os10.2.10

  • other

    paloaltonetworks / pan-os10.2.13

  • other

    paloaltonetworks / pan-os10.2.16

  • other

    paloaltonetworks / pan-os10.2.17

  • other

    paloaltonetworks / pan-os10.2.18

  • other

    paloaltonetworks / pan-os10.2.7

  • other

    paloaltonetworks / pan-os11.1.10

  • other

    paloaltonetworks / pan-os11.1.13

  • other

    paloaltonetworks / pan-os11.1.14

  • other

    paloaltonetworks / pan-os11.1.4

  • other

    paloaltonetworks / pan-os11.1.5

  • other

    paloaltonetworks / pan-os11.1.6

  • other

    paloaltonetworks / pan-os11.1.7

  • other

    paloaltonetworks / pan-os11.2.10

  • other

    paloaltonetworks / pan-os11.2.11

  • other

    paloaltonetworks / pan-os11.2.4

  • other

    paloaltonetworks / pan-os11.2.7

  • other

    paloaltonetworks / pan-os12.1.4

  • other

    paloaltonetworks / pan-os12.1.7

  • other

    paloaltonetworks / pan-os

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • paloaltonetworks

    cloud_ngfw

References & sources

Linked CVEs

IDCVE-2026-0286
Siemens ProductCERT Advisory SSA-104023 — CVE-2026-0286 | NEOSEC Intel