CVE-2026-0301 PUBLISHED

PAN-OS: Information Disclosure Vulnerability in URL Filtering

Assigner: palo_alto
Reserved: 03.11.2025 Published: 13.08.2026 Updated: 13.08.2026

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 1.7
CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 0.5

The risk of exploitation is lower for Prisma Access as it requires an authenticated user and the external network access to the management interface is restricted.

Product Status

Vendor Palo Alto Networks
Product Cloud NGFW
Versions Default: unknown
  • Version All is affected
Vendor Palo Alto Networks
Product PAN-OS
Versions Default: unaffected
  • Version 12.1.0 is unaffected
  • Version 11.2.0 is unaffected
  • affected from 11.1.0 to 11.1.17 (excl.)
  • affected from 10.2.0 to 10.2.8 (excl.)
Vendor Palo Alto Networks
Product Prisma Access
Versions Default: unknown
  • Version 12.1.0 is unaffected
  • Version 11.2.0 is unaffected
  • affected from 10.2.0 to 10.2.10 (excl.)

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Workarounds

Customers can mitigate this issue by limiting the Response Page Variables (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44) on their response page to only those in the Predefined URL Filtering Response Pages (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f). (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f) The variables that are included in our predefined response pages (user, url, category, pan_form) are not impacted by this vulnerability.

Credits

  • Jan Breig finder

References

Problem Types

  • CWE-908 Use of Uninitialized Resource CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data