CVE-2026-0272: falha de média gravidade em Palo Alto Networks PAN-OS
PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6epss 0.3%
probabilidade de exploração
0.3%top 84% das CVEs
exploração observada
nãonenhuma fonte reporta
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber
Produtos afetados
Palo Alto Networks · Cloud NGFWPalo Alto Networks · PAN-OSPalo Alto Networks · Prisma AccessCVEs relacionadas — Palo Alto Networks PAN-OS
No mesmo produto, das mais perigosas para as menos.
CVE-2024-3400CRITICALPAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectEPSS 100.0%KEVCVE-2024-0012CRITICALPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)EPSS 99.9%KEVCVE-2025-0108HIGHPAN-OS: Authentication Bypass in the Management Web InterfaceEPSS 98.5%KEVCVE-2026-0257HIGHPAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesEPSS 96.9%KEVCVE-2024-9474MEDIUMPAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management InterfaceEPSS 94.8%KEVCVE-2026-0300CRITICALPAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalEPSS 31.7%KEV