Description
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.
Published: 2026-08-13
Score: 0.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated network user can exploit a flaw in the URL Filtering feature of Palo Alto Networks PAN‑OS to read sensitive information that should be protected, leading to confidentiality compromise. The weakness stems from a failure to enforce proper authentication checks before exposing data, classified as CWE‑908. The exploit does not provide privilege escalation or denial of service, so the impact is limited to data leakage.

Affected Systems

Affected products are Palo Alto Networks Cloud NGFW, PAN‑OS, and Prisma Access. PAN‑OS 10.2.0 through 10.2.* require an upgrade to 10.2.8 or later. PAN‑OS 11.1.0 through 11.1.16‑h* require an upgrade to 11.1.16‑h1 or later, and PAN‑OS 12.1.0–12.1.1 are potentially vulnerable while 12.1.2–12.1.6‑h* are not affected. 12.1.2 and newer do not require action. Prisma Access 10.2.0 through 10.2.* must be upgraded to 10.2.10 or later; Prisma Access 12.1.2 through 12.1.* and 11.2.0 through 11.2.* are not impacted. Cloud NGFW is affected for all supported releases and requires a scheduled on‑demand upgrade with Palo Alto Networks support. Panorama is not affected.

Risk and Exploitability

The CVSS score of 0.5 indicates a very low severity risk. EPSS data is not available. The flaw can be triggered by any network participant with access to the device's URL Filtering interface and requires no authentication. Because the impact is limited to data leakage, the overall risk remains low, and the vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 13, 2026 at 04:58 UTC.

Remediation

Vendor Workaround

Customers can mitigate this issue by limiting the Response Page Variables https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44 on their response page to only those in the Predefined URL Filtering Response Pages https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f . https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f The variables that are included in our predefined response pages (user, url, category, pan_form) are not impacted by this vulnerability.


OpenCVE Recommended Actions

  • Upgrade PAN‑OS to a supported fixed version (for example, upgrade to 10.2.8 or later for the 10.2 series, upgrade to 11.1.16‑h1 or later for the 11.1 series, and for any 12.1.0–12.1.1 systems upgrade to 12.1.2 or later).
  • Schedule an on‑demand software upgrade of Cloud NGFW with Palo Alto Networks support.
  • Apply the vendor‑provided workaround by limiting the URL Filtering response page to use only the predefined variables (user, url, category, pan_form).

Generated by OpenCVE AI on August 13, 2026 at 04:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Paloaltonetworks
Paloaltonetworks cloud Ngfw
Paloaltonetworks pan-os
Paloaltonetworks prisma Access
CPEs cpe:2.3:a:paloaltonetworks:cloud_ngfw:-:*:*:*:*:aws:*:*
cpe:2.3:a:paloaltonetworks:cloud_ngfw:-:*:*:*:*:azure:*:*
cpe:2.3:a:paloaltonetworks:prisma_access:*:*:*:*:innovation:*:*:*
cpe:2.3:a:paloaltonetworks:prisma_access:*:*:*:*:preferred:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:-:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:11.1.16:-:*:*:*:*:*:*
Vendors & Products Paloaltonetworks
Paloaltonetworks cloud Ngfw
Paloaltonetworks pan-os
Paloaltonetworks prisma Access
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:AWS:*:*
cpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:Azure:*:*
cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:prisma_access:*:*:*:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:cloud_ngfw:all:*:aws:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:cloud_ngfw:all:*:azure:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:pan-os:11.2.0:*:*:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:pan-os:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access:*:*:*:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access:11.2.0:*:*:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access:12.1.0:*:*:*:*:*:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
Title PAN-OS: Information Disclosure Vulnerability in URL Filtering
First Time appeared Palo Alto Networks
Palo Alto Networks cloud Ngfw
Palo Alto Networks pan-os
Palo Alto Networks prisma Access
Weaknesses CWE-908
CPEs cpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:AWS:*:*
cpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:Azure:*:*
cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.0:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.1:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.2:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.3:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.4:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.5:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.6:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:10.2.7:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.0:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.10:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.11:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.12:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.13:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.14:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.15:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:-:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.1:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.2:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.3:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.4:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.5:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.6:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.8:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.1.9:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:prisma_access:*:*:*:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks cloud Ngfw
Palo Alto Networks pan-os
Palo Alto Networks prisma Access
References
Metrics cvssV4_0

{'score': 0.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Cloud Ngfw Pan-os Prisma Access
Paloaltonetworks Cloud Ngfw Pan-os Prisma Access
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-14T18:27:26.549Z

Reserved: 2025-11-03T20:44:59.306Z

Link: CVE-2026-0301

cve-icon Vulnrichment

Updated: 2026-08-13T13:32:33.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T03:16:46.097

Modified: 2026-08-28T14:49:09.613

Link: CVE-2026-0301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T05:00:10Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource