Palo Alto Networks · Pan-Os · CVE-2026-0286
**Name of the Vulnerable Software and Affected Versions**
PAN-OS versions prior to 12.1.8
PAN-OS versions prior to 11.2.13
PAN-OS versions prior to 11.1.16
PAN-OS versions prior to 10.2.18-h8
**Description**
A command injection issue exists in the management plane of the software, specifically within the Command Line Interface (CLI). This allows an authenticated administrator to break out of the CLI and execute arbitrary operating system commands with root privileges on the underlying system. The risk is reduced when CLI access is restricted to a limited group of administrators.
**Recommendations**
Update to version 12.1.8 or later.
Update to version 11.2.13 or later.
Update to version 11.1.16 or later.
Update to version 10.2.18-h8 or later.
As a temporary mitigation, apply Threat ID 510036 (content version 9122-10145 or later) for users with a Threat Prevention subscription who are decrypting inbound management traffic.