Impact
An unauthenticated network user can exploit a flaw in the URL Filtering feature of Palo Alto Networks PAN‑OS to read sensitive information that should be protected, leading to confidentiality compromise. The weakness stems from a failure to enforce proper authentication checks before exposing data, classified as CWE‑908. The exploit does not provide privilege escalation or denial of service, so the impact is limited to data leakage.
Affected Systems
Affected products are Palo Alto Networks Cloud NGFW, PAN‑OS, and Prisma Access. PAN‑OS 10.2.0 through 10.2.* require an upgrade to 10.2.8 or later. PAN‑OS 11.1.0 through 11.1.16‑h* require an upgrade to 11.1.16‑h1 or later, and PAN‑OS 12.1.0–12.1.1 are potentially vulnerable while 12.1.2–12.1.6‑h* are not affected. 12.1.2 and newer do not require action. Prisma Access 10.2.0 through 10.2.* must be upgraded to 10.2.10 or later; Prisma Access 12.1.2 through 12.1.* and 11.2.0 through 11.2.* are not impacted. Cloud NGFW is affected for all supported releases and requires a scheduled on‑demand upgrade with Palo Alto Networks support. Panorama is not affected.
Risk and Exploitability
The CVSS score of 0.5 indicates a very low severity risk. EPSS data is not available. The flaw can be triggered by any network participant with access to the device's URL Filtering interface and requires no authentication. Because the impact is limited to data leakage, the overall risk remains low, and the vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment