CVE-2026-0286
Siemens ProductCERT Advisory SSA-104023
Description
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Metrics
Weakness classes (CWE)
CWE-78Base
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-11 13:17 UTC· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- Affected: RUGGEDCOM APE1808
- Reference: https://cert-portal.siemens.com/productcert/html/ssa-104023.html
Affected operating systems
other
paloaltonetworks / pan-os10.2.10
other
paloaltonetworks / pan-os10.2.13
other
paloaltonetworks / pan-os10.2.16
other
paloaltonetworks / pan-os10.2.17
other
paloaltonetworks / pan-os10.2.18
other
paloaltonetworks / pan-os10.2.7
other
paloaltonetworks / pan-os11.1.10
other
paloaltonetworks / pan-os11.1.13
other
paloaltonetworks / pan-os11.1.14
other
paloaltonetworks / pan-os11.1.4
other
paloaltonetworks / pan-os11.1.5
other
paloaltonetworks / pan-os11.1.6
other
paloaltonetworks / pan-os11.1.7
other
paloaltonetworks / pan-os11.2.10
other
paloaltonetworks / pan-os11.2.11
other
paloaltonetworks / pan-os11.2.4
other
paloaltonetworks / pan-os11.2.7
other
paloaltonetworks / pan-os12.1.4
other
paloaltonetworks / pan-os12.1.7
other
paloaltonetworks / pan-os
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
paloaltonetworks
cloud_ngfw
References & sources
- https://security.paloaltonetworks.com/CVE-2026-0286vendor-advisory
- https://cert-portal.siemens.com/productcert/html/ssa-104023.html
- https://security.paloaltonetworks.com/
- https://security.paloaltonetworks.com/CVE-2026-0282vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0287vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0266vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0279vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0273vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0285vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0284vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0272vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0281vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0283vendor-advisory
- https://security.paloaltonetworks.com/CVE-2026-0280vendor-advisory
Linked CVEs
- CVE-2026-0288
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow…
highCVSSv3 7.5 - CVE-2026-0287
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access t…
highCVSSv3 7.5 - CVE-2026-0285
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with netw…
mediumCVSSv3 4.9 - CVE-2026-0284
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthentic…
criticalCVSSv3 9.9 - CVE-2026-0283
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker…
highCVSSv3 7.2 - CVE-2026-0282
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the manag…
mediumCVSSv3 6.5 - CVE-2026-0281
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to…
highCVSSv3 7.1 - CVE-2026-0280
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to by…
highCVSSv3 7.2 - CVE-2026-0279
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/…
mediumCVSSv3 6.1 - CVE-2026-0273
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrict…
highCVSSv3 7.2 - CVE-2026-0272
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Comm…
highCVSSv3 7.2 - CVE-2026-0266
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to stor…
mediumCVSSv3 4.8