Palo Alto Networks PAN-OS® 软件中存在一个命令注入漏洞,允许经过身份验证的管理员绕过系统限制,以 root 用户身份执行任意命令。利用该漏洞需要满足两个条件:用户必须拥有 PAN-OS CLI 访问权限,且设备必须已配置 Luna 硬件安全模块(HSM)。 当 CLI 访问权限被限制在有限的管理员群体内时,此问题带来的安全风险会显著降低。 Panorama、Cloud NGFW 和 Prisma® Access 不受此漏洞影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | - | - |
|
| Palo Alto Networks | PAN-OS | 12.2.0 ~ 12.2.3 |
cpe:2.3:o:palo_alto_networks:pan-os:12.2.2:*:*:*:*:*:*:*
|
|
| Palo Alto Networks | Prisma Access | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0307 | 5.9 MEDIUM | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-0306 | 5.8 MEDIUM | Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows |
| CVE-2026-0310 | 5.2 MEDIUM | PAN-OS: Buffer Overflow Vulnerability via XML Processing |
| CVE-2026-0304 | 4.8 MEDIUM | Cortex XDR Broker VM: Privilege Escalation Vulnerability |
| CVE-2026-0305 | 4.3 MEDIUM | Prisma Access Agent: Information Disclosure Vulnerability on Linux |
| CVE-2026-0303 | 2.4 LOW | Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File |
| CVE-2026-0302 | 1.1 LOW | Checkov by Prisma Cloud: OS Command Injection Vulnerability |
| CVE-2026-0308 | 0.4 LOW | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface |
No comments yet