← All Advisories

Palo Alto Networks PAN-OS Management Plane Command Injection Allows Authenticated Administrator to Execute Arbitrary Root-Level OS Commands

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2026-0286

Key Details

CVECVE-2026-0286
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-08-11
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPalo Alto Networks PAN-OS and Siemens RUGGEDCOM APE1808
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Exploitation prediction (EPSS)1.67% probability of exploitation in the next 30 days (76% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksPAN-OS
SiemensRUGGEDCOM APE1808
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root.

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma Access® are not impacted by this vulnerability. (NVD)

What to Do

Monitor Palo Alto Networks's and Siemens's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0286
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0286
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0286