CVE-2026-0285
PAN-OS Schwachstellenanalyse und -minderung

Überblick

CVE-2026-0285 is a Server-Side Request Forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software that enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The vulnerability was discovered internally by Palo Alto Networks and publicly disclosed on July 8, 2026. Affected versions span PAN-OS 10.2.x (before 10.2.18-h8), 11.1.x (before 11.1.16), 11.2.x (before 11.2.13), and 12.1.x (before 12.1.8). Panorama, Cloud NGFW, and Prisma® Access are not affected. It carries a CVSS v4.0 base score of 4.7 (Medium) (PAN Advisory, GitHub Advisory).

Technische Details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the PAN-OS management web interface fails to sufficiently validate or restrict outbound requests initiated by user-supplied input, allowing the firewall to be used as a proxy to reach internal services. Exploitation requires an attacker to already hold authenticated administrator credentials and have network access to the management web interface — a high-privilege precondition that significantly limits the attack surface. The risk is greatest when the management interface is exposed to the internet or untrusted networks, either directly or through a dataplane interface with a management profile (PAN Advisory). No public proof-of-concept code or detailed technical write-ups have been identified at this time.

Aufprall

Successful exploitation allows an authenticated administrator to make unauthorized HTTP requests originating from the firewall to internal backend services that would otherwise be inaccessible from external networks, resulting in a high integrity impact on the vulnerable system and a low confidentiality impact. This could enable an attacker to interact with or manipulate internal services (e.g., metadata APIs, internal management endpoints) that rely on network-level trust from the firewall. Availability is not impacted, and there is no assessed impact on subsequent systems. The scope of impact is limited to environments where the management interface is accessible from untrusted networks (PAN Advisory, GitHub Advisory).

Ausnutzbarkeit

As of the disclosure date, Palo Alto Networks is not aware of any malicious exploitation of this vulnerability in the wild, and no public proof-of-concept exploit has been reported (PAN Advisory). The CVSS v4.0 exploit maturity is rated "UNREPORTED," and the EPSS score is approximately 0.49%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for high-privilege (administrator) credentials, making opportunistic mass exploitation unlikely.

Ausnutzungsschritte

  1. Reconnaissance: Identify internet-facing PAN-OS management web interfaces using tools like Shodan or Censys, filtering for known PAN-OS management portal fingerprints on TCP/443 or TCP/4443.
  2. Credential Acquisition: Obtain valid administrator credentials for the target PAN-OS device through phishing, credential stuffing, or insider access — a prerequisite for exploitation.
  3. Authenticate to Management Interface: Log in to the PAN-OS management web interface using the acquired administrator credentials.
  4. Craft SSRF Payload: Identify input fields or API endpoints within the management interface that accept URLs or host/IP parameters and submit a crafted request pointing to an internal service (e.g., http://169.254.169.254/ for cloud metadata, or internal RFC-1918 addresses).
  5. Trigger Unauthorized Request: Submit the crafted request; the firewall processes it and forwards the request to the specified internal target, returning the response to the attacker.
  6. Enumerate Internal Services: Use the SSRF primitive to probe internal network services, cloud metadata endpoints, or other backend systems that trust the firewall's IP, potentially gathering credentials or configuration data for further lateral movement (PAN Advisory).

Indikatoren für Kompromittierung

  • Network: Unusual outbound HTTP/HTTPS requests originating from the firewall's management IP to internal RFC-1918 addresses or cloud metadata endpoints (e.g., 169.254.169.254); unexpected connections from the management interface to internal services not part of normal firewall operations.
  • Logs: PAN-OS management web interface access logs showing authenticated administrator sessions followed by requests to unusual or internal URLs; web server logs on internal services showing requests sourced from the firewall's management IP.
  • Behavioral: Administrator accounts accessing the management interface from unexpected source IPs or at unusual times; repeated or scripted requests to management API endpoints that accept URL or host parameters.

Risikominderung und Problemumgehungen

Palo Alto Networks has released patched versions addressing this vulnerability. Organizations should upgrade to the following minimum fixed versions based on their branch: PAN-OS 10.2 → 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, or 10.2.18-h8; PAN-OS 11.1 → 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, or 11.1.16; PAN-OS 11.2 → 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, or 11.2.13; PAN-OS 12.1 → 12.1.4-h8, 12.1.7-h2, or 12.1.8. As a critical workaround, restrict management interface access to only trusted internal IP addresses per Palo Alto Networks' best practice guidelines. Customers with a Threat Prevention subscription can enable Threat ID 510030 (from content version 9122-10145 or later) to block attacks, though this requires SSL decryption of inbound management traffic (PAN Advisory).

Reaktionen der Community

The vulnerability was noted by security monitoring services including HKCERT, which published a bulletin covering multiple Palo Alto Networks vulnerabilities disclosed in the same advisory cycle. Automated CVE tracking feeds (Mastodon/RedPacketSecurity, Bluesky) flagged the advisory shortly after publication. No significant independent researcher commentary or media coverage beyond routine CVE tracking has been identified, consistent with the moderate severity and limited exploitability of this issue (PAN Advisory).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt PAN-OS Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NeinJaJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NeinJaJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NeinJaJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NeinJaJul 09, 2026
CVE-2026-0283MEDIUM4.5
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NeinJaJul 09, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement