PAN-OS
CVE-2026-0308: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cloud NGFW | Not affected |
| PAN-OS 12.2 | Not affected |
| PAN-OS 12.1 | 12.1.10 or later |
| PAN-OS 11.2 | 11.2.13-h2 or later |
| PAN-OS 11.1 | 11.1.16-h2 or later |
| Prisma Access | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Am I affected?
No special configuration is required to be affected by this issue.
Workarounds
No known workarounds exist for this issue.
Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability:
- Route incoming traffic for the MGT port through a DP port (https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id59206398-3dab-4b2f-9b4b-7ea500d036ba), e.g., enabling management profile on a DP interface for management access.
- Replace the Certificate for Inbound Traffic Management (https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id112f7714-8995-4496-bbf9-781e63dec71c).
- Decrypt inbound traffic to the management interface so the firewall can inspect it (https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#idbbd82587-17a2-42b4-9245-d3714e1e13a2).
- Enable threat prevention on the inbound traffic to management services.
Please note that this Threat ID requires SSL Decryption.
Exploitation
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.