{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-E824A93F",
  "slug": "cve-2026-0310-pan-os-xml-buffer-overflow-unauth-root",
  "title": "PAN-OS XML overflow can give unauth root on PA-Series",
  "aliases": [
    "CVE-2026-0310",
    "PAN-OS XML buffer overflow"
  ],
  "summary": "A buffer overflow in PAN-OS XML processing lets an unauthenticated attacker with network access to the management web or dataplane interface cause DoS on VM-Series or execute arbitrary code as root on PA-Series hardware firewalls. Upgrade to the fixed PAN-OS / Prisma Access builds for your train.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Cloud NGFW is listed as affected with no fixed version in the pack; confirm current Palo Alto guidance for Cloud NGFW separately from on-prem PAN-OS trains.",
  "firstObservedAt": "2026-09-10T05:21:28.646Z",
  "lastObservedAt": "2026-09-10T05:30:25.944Z",
  "publishedAt": "2026-09-20T19:55:58.761Z",
  "reviewedAt": "2026-09-20T19:55:54.414Z",
  "expiresAt": "2026-09-10T05:30:25.944Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "pan-advisory",
      "label": "Palo Alto Networks security advisory CVE-2026-0310",
      "url": "https://security.paloaltonetworks.com/CVE-2026-0310",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-10T05:21:28.646Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-0310",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0310",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-10T05:30:25.944Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-0310-pan-os-xml-buffer-overflow-unauth-root",
      "sourceType": "other_primary",
      "observedAt": "2026-09-10T00:00:00.000Z"
    }
  ],
  "artifacts": [
    {
      "id": "pan-os",
      "artifactClass": "package",
      "ecosystem": "paloalto",
      "name": "PAN-OS",
      "version": ">=12.2.0 <12.2.3 || >=12.1.0 <12.1.4-h10 || >=11.2.0 <11.2.4-h21 || >=11.1.0 <11.1.4-h36 || >=10.2.0 <10.2.7-h37",
      "defanged": false
    },
    {
      "id": "prisma-access",
      "artifactClass": "package",
      "ecosystem": "paloalto",
      "name": "Prisma Access",
      "version": ">=11.2.0 <11.2.4-h21 || >=10.2.0 <10.2.7-h37",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-10T05:21:28.646Z",
      "eventType": "disclosure",
      "summary": "Palo Alto Networks disclosed CVE-2026-0310 PAN-OS XML processing buffer overflow.",
      "sourceIds": [
        "pan-advisory",
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-10T12:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog coverage for CVE-2026-0310.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Impact differs by platform: DoS on VM-Series vs arbitrary code as root on PA-Series hardware per vendor advisory.",
    "Cloud NGFW is listed affected without a pack fixed version — confirm live Palo Alto guidance.",
    "This campaign does not invent CVSS scores; severity is taken as critical from the unauth root/DoS impact described by the vendor."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-0310-pan-os-xml-buffer-overflow-unauth-root/corrections"
}
