IM
IronMonkey Threat Research

CVE-2026-0282 MEDIUM

Published: 2026-07-09 | Last Modified: 2026-08-11 | Status: Modified

Description

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability.

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactLOW
Availability ImpactLOW

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 2.5

Base Score: 2.7 (LOW)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

Attack VectorNETWORK
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredNONE
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityLOW
Vulnerability AvailabilityLOW
Subsequent ConfidentialityNONE
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-20

Affected Products

Vendor Product Version Update Type
paloaltonetworks pan-os * <built-in method update of dict object at 0x73d07e87abc0> Operating System
paloaltonetworks pan-os * <built-in method update of dict object at 0x73d04ee307c0> Operating System
paloaltonetworks pan-os * <built-in method update of dict object at 0x73d04cbfb240> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Notification
Message here