CVE-2026-0284
PAN-OS 취약성 분석 및 완화

개요

CVE-2026-0284 is an XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software. It enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. The vulnerability was discovered internally by Palo Alto Networks and publicly disclosed on July 8, 2026. Affected versions span PAN-OS 10.2.x (before 10.2.7-h36), 11.1.x (before 11.1.16), 11.2.x (before 11.2.13), and 12.1.x (before 12.1.8); Panorama, Cloud NGFW, and Prisma® Access are not affected. The CVSS v4.0 base score is 4.7 (Medium), while the CVSS v3.1 base score is 9.9 (Critical) (PAN Advisory, GitHub Advisory).

기술적 세부 사항

The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — 'Injection'), specifically an XML injection pattern (CAPEC-250). The vulnerability exists in the LSVPN satellite communication handling within PAN-OS, where user-supplied input is not properly sanitized before being incorporated into XML structures processed by downstream components. An unauthenticated attacker with network access to the LSVPN portal can craft and send malicious XML content to the affected endpoint, causing the firewall to process attacker-controlled XML that may alter data interpretation or expose sensitive configuration. Exploitation requires the firewall to have LSVPN configured with at least one satellite; administrators can verify exposure by running show config running | match satellite from the PAN-OS CLI (PAN Advisory).

영향

Successful exploitation can result in information disclosure of sensitive LSVPN-related data (e.g., satellite configuration details) and corruption of internal LSVPN satellite data, potentially disrupting VPN connectivity for satellite sites. The subsequent system confidentiality impact is rated High under CVSS v4.0, indicating that data accessible beyond the directly vulnerable component may be exposed. While availability of the vulnerable system itself is not directly impacted, integrity and availability of downstream satellite systems may be degraded, potentially affecting branch-office connectivity in large-scale VPN deployments (PAN Advisory, GitHub Advisory).

악용 가능성

As of the time of disclosure, Palo Alto Networks is not aware of any malicious exploitation of this issue in the wild, and no public proof-of-concept exploit code has been reported (PAN Advisory). The EPSS score is approximately 0.45–0.50%, indicating a low near-term probability of exploitation. The exploit maturity is listed as "Unreported" by the vendor. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

착취 단계

  1. Reconnaissance: Identify internet-facing Palo Alto Networks firewalls running PAN-OS with LSVPN (GlobalProtect portals with satellite configuration) using tools such as Shodan or Censys, targeting affected version ranges (PAN-OS 10.2.x, 11.1.x, 11.2.x, 12.1.x).
  2. Confirm LSVPN exposure: Probe the GlobalProtect portal endpoint to determine if LSVPN satellite functionality is enabled and accessible from the network.
  3. Craft malicious XML payload: Construct an XML injection payload containing special characters or malicious XML elements (e.g., entity references, injected tags) designed to alter the structure of XML data processed by the LSVPN satellite handling component.
  4. Deliver payload: Send the crafted request to the LSVPN-related network endpoint on the firewall without authentication, leveraging the lack of input sanitization.
  5. Achieve objective: Depending on the injected content, extract disclosed information from the server's XML response (information disclosure) or corrupt LSVPN satellite configuration data, potentially disrupting satellite VPN connectivity (PAN Advisory).

타협의 징후

  • Network: Unexpected or malformed XML content in traffic directed at GlobalProtect/LSVPN portal endpoints; anomalous unauthenticated requests to LSVPN satellite communication interfaces from external or untrusted IP addresses.
  • Logs: PAN-OS system logs showing XML parsing errors or unexpected data in LSVPN satellite processing; GlobalProtect portal logs reflecting unusual unauthenticated connection attempts with malformed payloads.
  • Threat Prevention: Alerts triggered by Threat ID 510031 (available from Applications and Threats content version 9122-10145 and later) applied to the GlobalProtect interface (PAN Advisory).

완화 및 해결 방법

Palo Alto Networks has released patched versions across all affected branches. Administrators should upgrade to the following minimum fixed versions: PAN-OS 10.2 → 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, or 10.2.18-h8; PAN-OS 11.1 → 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, or 11.1.16; PAN-OS 11.2 → 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, or 11.2.13; PAN-OS 12.1 → 12.1.4-h8, 12.1.7-h2, or 12.1.8. No configuration-based workaround exists; however, customers with a Threat Prevention subscription can enable Threat ID 510031 (content version 9122-10145+) with a vulnerability protection profile applied to the GlobalProtect interface for limited interim coverage. Organizations not using LSVPN satellites are not exposed (PAN Advisory).

커뮤니티 반응

The vulnerability received routine coverage from security aggregators and vulnerability tracking services shortly after disclosure, including mentions on Mastodon security feeds, HKCERT, Tenable, and BleepingComputer (in the context of an InfraTrust infrastructure patching report). No notable independent researcher commentary or significant community controversy has been identified. The vendor's internal discovery and moderate urgency rating have kept community reaction measured (PAN Advisory).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 PAN-OS 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
아니요Jul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
아니요Jul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
아니요Jul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
아니요Jul 09, 2026
CVE-2026-0283MEDIUM4.5
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
아니요Jul 09, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자