CVE-2025-4615
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:Amber
- EPSS probability
- 0.79%
- CWE
- CWE-83
- Published
- 2025-10-09
- Last modified
- 2026-04-01
Affected products
- Palo Alto Networks Cloud NGFW
- Palo Alto Networks PAN-OS
- Palo Alto Networks PAN-OS
- Palo Alto Networks PAN-OS
- Palo Alto Networks PAN-OS
- Palo Alto Networks Prisma Access
Weakness type
Related vulnerabilities
- CVE-2026-45118 — MyBB: Contact page reflected XSS
- CVE-2026-45733 — Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app
- CVE-2026-15920 — Potential cross-site scripting via URLField values in the admin
- CVE-2026-62324 — Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
- CVE-2026-59727 — Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- CVE-2026-49276 — Kirby: Self cross-site scripting (self-XSS) in the writer field
- CVE-2026-58263 — Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
- CVE-2026-48591 — Stored XSS via unescaped HTML attribute values in earmark