
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0284 is an XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software. It enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. The vulnerability was discovered internally by Palo Alto Networks and publicly disclosed on July 8, 2026. Affected versions span PAN-OS 10.2.x (before 10.2.7-h36), 11.1.x (before 11.1.16), 11.2.x (before 11.2.13), and 12.1.x (before 12.1.8); Panorama, Cloud NGFW, and Prisma® Access are not affected. The CVSS v4.0 base score is 4.7 (Medium), while the CVSS v3.1 base score is 9.9 (Critical) (PAN Advisory, GitHub Advisory).
The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — 'Injection'), specifically an XML injection pattern (CAPEC-250). The vulnerability exists in the LSVPN satellite communication handling within PAN-OS, where user-supplied input is not properly sanitized before being incorporated into XML structures processed by downstream components. An unauthenticated attacker with network access to the LSVPN portal can craft and send malicious XML content to the affected endpoint, causing the firewall to process attacker-controlled XML that may alter data interpretation or expose sensitive configuration. Exploitation requires the firewall to have LSVPN configured with at least one satellite; administrators can verify exposure by running show config running | match satellite from the PAN-OS CLI (PAN Advisory).
Successful exploitation can result in information disclosure of sensitive LSVPN-related data (e.g., satellite configuration details) and corruption of internal LSVPN satellite data, potentially disrupting VPN connectivity for satellite sites. The subsequent system confidentiality impact is rated High under CVSS v4.0, indicating that data accessible beyond the directly vulnerable component may be exposed. While availability of the vulnerable system itself is not directly impacted, integrity and availability of downstream satellite systems may be degraded, potentially affecting branch-office connectivity in large-scale VPN deployments (PAN Advisory, GitHub Advisory).
Palo Alto Networks has released patched versions across all affected branches. Administrators should upgrade to the following minimum fixed versions: PAN-OS 10.2 → 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, or 10.2.18-h8; PAN-OS 11.1 → 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, or 11.1.16; PAN-OS 11.2 → 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, or 11.2.13; PAN-OS 12.1 → 12.1.4-h8, 12.1.7-h2, or 12.1.8. No configuration-based workaround exists; however, customers with a Threat Prevention subscription can enable Threat ID 510031 (content version 9122-10145+) with a vulnerability protection profile applied to the GlobalProtect interface for limited interim coverage. Organizations not using LSVPN satellites are not exposed (PAN Advisory).
The vulnerability received routine coverage from security aggregators and vulnerability tracking services shortly after disclosure, including mentions on Mastodon security feeds, HKCERT, Tenable, and BleepingComputer (in the context of an InfraTrust infrastructure patching report). No notable independent researcher commentary or significant community controversy has been identified. The vendor's internal discovery and moderate urgency rating have kept community reaction measured (PAN Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."