Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload.
The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW is not affected by this vulnerability.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0279 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 12:43
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| First Time |
Paloaltonetworks
Paloaltonetworks pan-os |
|
| References | () https://security.paloaltonetworks.com/CVE-2026-0279 - Vendor Advisory |
09 Jul 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 19:16
Updated : 2026-07-13 12:43
NVD link : CVE-2026-0279
Mitre link : CVE-2026-0279
CVE.ORG link : CVE-2026-0279
JSON object : View
Products Affected
paloaltonetworks
- pan-os
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
