CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering
Description
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| Cloud NGFW | All on AWS* All on Azure* | None on AWS* None on Azure* |
| PAN-OS 12.1 | None | All |
| PAN-OS 11.2 | None | All |
| PAN-OS 11.1 | < 11.1.16-h1 < 11.1.17 | >= 11.1.16-h1 >= 11.1.17 |
| PAN-OS 10.2 | < 10.2.8 | >= 10.2.8 |
| Prisma Access 12.1 | None | All |
| Prisma Access 11.2 | None | All |
| Prisma Access 10.2 | < 10.2.10 | >= 10.2.10 |
Note: Palo Alto Networks Prisma Access and Cloud NGFW will upgrade all customers during the next scheduled maintenance cycle. Customers who require an upgrade prior to this cycle should contact Palo Alto Networks Support or their account teams to schedule an on-demand software upgrade window.
* CNGFW AWS and Azure are not impacted if running version 11.2 (Please contact support if you need help verifying your current version.)
Required Configuration for Exposure
This issue applies only to firewalls where URL filtering is enabled with customized response page.
To check if a PAN-OS device has Customized URL Filtering response pages, navigate to: Device > Response Pages
If you have imported a custom URL Filtering HTML response page, your device is affected.
Severity: LOW, Suggested Urgency: MODERATE
CVSS-BT: 1.7 / CVSS-B: 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
The risk of exploitation is lower for Prisma Access as it requires an authenticated user and the external network access to the management interface is restricted.
LOW
- CVSS-BT: 0.5 /CVSS-B: 2.1 (CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Weakness Type and Impact
CWE-908 Use of Uninitialized Resource
CAPEC-37 Retrieve Embedded Sensitive Data
Solution
| Version | Minor Version | Suggested Solution |
|---|---|---|
| Cloud NGFW* | Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. | |
| PAN-OS 12.1 | 12.1.2 through 12.1.6-h* | No action needed. |
| PAN-OS 11.2 | 11.2.0 through 11.2.12 | No action needed. |
| PAN-OS 11.1 |
11.1.0 through 11.1.16-h* | Upgrade to 11.1.16-h1 or 11.1.17 or later. |
| PAN-OS 10.2 |
10.2.0 through 10.2.* | Upgrade to 10.2.8 or 11.1.17 or later. |
| All older unsupported PAN-OS versions | Upgrade to a supported fixed version. | |
| Prisma Access 12.1 | 12.1.2 through 12.1.* | No action needed. |
| Prisma Access 11.2 | 11.2.0 through 11.2* | No action needed. |
| Prisma Access 10.2 |
10.2.0 through 10.2.* | Upgrade to 10.2.10 or later. |
* See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.
Workarounds and Mitigations
Customers can mitigate this issue by limiting the Response Page Variables on their response page to only those in the Predefined URL Filtering Response Pages. The variables that are included in our predefined response pages (user, url, category, pan_form) are not impacted by this vulnerability.
Acknowledgments
CPEs
cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:-:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.15:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.14:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.13:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.12:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.11:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.10:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.9:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.8:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.6:*:*:*:*:*:*:*
CPE Applicability
- cpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:AWS:*:* is vulnerable from (including)all
- ORcpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:Azure:*:* is vulnerable from (including)all
- or
- cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.0 and up to (excluding)11.1.17
- ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.16 and up to (excluding)11.1.16-h1
- ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.0 and up to (excluding)10.2.8
- or
- cpe:2.3:o:palo_alto_networks:prisma_access:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.0 and up to (excluding)10.2.10