CVE-2026-0301

PAN-OS: Information Disclosure Vulnerability in URL Filtering

Severity
Low 1.7
CVSS 4.0
Exploited
Not listed
EPSS
0.003
24.2th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 13, 2026
Assigned by palo_alto

Description

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

Weakness: CWE-908

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Jan Breig

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW*Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.PAN-OS 12.1 12.1.2 through 12.1.6-h*No action needed.PAN-OS 11.2 11.2.0 through 11.2.12 No action needed. PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or later. PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.16-h1 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access 12.1 12.1.2 through 12.1.* No action needed.Prisma Access 11.2 11.2.0 through 11.2* No action needed. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.

Something wrong here?