CVE-2026-0301

Summary

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksCloud NGFWAllaffected
Palo Alto NetworksPAN-OS12.1.0unaffected
Palo Alto NetworksPAN-OS11.2.0unaffected
Palo Alto NetworksPAN-OS11.1.0 < 11.1.17affected
Palo Alto NetworksPAN-OS10.2.0 < 10.2.8affected
Palo Alto NetworksPrisma Access12.1.0unaffected
Palo Alto NetworksPrisma Access11.2.0unaffected
Palo Alto NetworksPrisma Access10.2.0 < 10.2.10affected

Weaknesses

  • CWE-908: CWE-908 Use of Uninitialized Resource

Workarounds

Customers can mitigate this issue by limiting the Response Page Variables (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44) on their response page to only those in the Predefined URL Filtering Response Pages (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f). (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f) The variables that are included in our predefined response pages (user, url, category, pan_form) are not impacted by this vulnerability.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References