CVE-2026-0286
CVE-2026-0286: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Palo Alto
1 advisory- Advisory severityHigh8.5
High [CVE-2026-0286] PAN-OS: Authenticated Command Injection in CLI
CVE-2026-0286Source published
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
- Affected products in this advisory
- PAN-OS
- Source-reported affected versions
- PAN-OS < 12.1.8
- PAN-OS < 11.2.13
- PAN-OS < 11.1.16
- PAN-OS < 10.2.18-h8
- Source-reported fixed versions
- PAN-OS >= 12.1.8
- PAN-OS >= 12.1.7-h2
- PAN-OS >= 12.1.4-h8
- PAN-OS >= 11.2.13
14 more entries in the full advisory.
- Mitigation guidance
- VersionMinor VersionSuggested SolutionCloud NGFW AllNo action needed.
- PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later.
- Workarounds
- Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510036 (from Applications and Threats content version 9122-10145 and later).
- For these Threat IDs to protect against attacks for this vulnerability:
- Route incoming traffic for the MGT port through a DP port, e.g., enabling management profile on a DP interface for management access.Replace the Certificate for Inbound Traffic Management.
- Decrypt inbound traffic to the management interface so the firewall can inspect it.Enable threat prevention on the inbound traffic to management services.
1 more entries in the full advisory.
Android app · Google Play
Monitor future Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.