CVE-2026-0301
PAN-OS Análisis y mitigación de vulnerabilidades

Vista general

CVE-2026-0301 is an information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software that enables an unauthenticated user with network access to obtain sensitive information. It was published on August 12, 2026, and was discovered externally by researcher Jan Breig. Affected products include PAN-OS 10.2.x (before 10.2.8), PAN-OS 11.1.x (before 11.1.16-h1), Cloud NGFW (all versions on AWS and Azure unless running 11.2+), and Prisma Access 10.2.x (before 10.2.10); PAN-OS 11.2, 12.1, and Panorama are not affected. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 1.7 (Low) reflecting exploit maturity and environmental factors (Palo Alto Advisory, Github Advisory).

Técnicas

The vulnerability is classified as CWE-908 (Use of Uninitialized Resource), associated with CAPEC-37 (Retrieve Embedded Sensitive Data). The flaw exists specifically in the URL Filtering feature when a customized response page is configured — if a firewall has imported a custom URL Filtering HTML response page (configurable under Device > Response Pages), uninitialized resource data may be exposed in the response page content served to users. An unauthenticated attacker with network access can trigger this condition by interacting with the URL filtering response mechanism, potentially retrieving sensitive information embedded in the uninitialized resource. The vulnerability does not require privileges or user interaction, but does require the specific configuration of a customized URL filtering response page to be exploitable (Palo Alto Advisory).

Impacto

Successful exploitation results in a confidentiality impact — an unauthenticated network-adjacent attacker can obtain sensitive information exposed through the URL filtering response page mechanism. There is no integrity or availability impact. The scope of exposed data is limited to what may be present in uninitialized memory surfaced via the response page variables, and the vulnerability does not enable lateral movement or code execution. For Prisma Access, the risk is further reduced as exploitation requires an authenticated user and management interface access is restricted (Palo Alto Advisory, Github Advisory).

Explotabilidad

As of the advisory publication date, Palo Alto Networks is not aware of any malicious exploitation of this issue in the wild, and no public proof-of-concept exploit exists. The EPSS score is approximately 0.313% (24th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and exploit maturity is rated as "Unreported" by the vendor. Exploitation is not automatable and requires the specific precondition of a customized URL filtering response page being configured (Palo Alto Advisory, Github Advisory).

Mitigación y soluciones alternativas

Palo Alto Networks has released fixed versions: PAN-OS 10.2.8 or later, PAN-OS 11.1.16-h1 or later, and Prisma Access 10.2.10 or later. PAN-OS 11.2 and 12.1 require no action. Cloud NGFW customers will be upgraded during the next scheduled maintenance cycle; those requiring earlier upgrades should contact Palo Alto Networks Support. As a configuration-based workaround, administrators can limit the Response Page Variables on their custom response page to only those included in the predefined URL Filtering Response Pages (user, url, category, pan_form), which are not impacted by this vulnerability. Administrators should verify exposure by navigating to Device > Response Pages and checking whether a custom URL Filtering HTML response page has been imported (Palo Alto Advisory).

Reacciones de la comunidad

The vulnerability was part of a broader August 2026 Palo Alto Networks patch release addressing 11 vulnerabilities across PAN-OS, GlobalProtect, and Prisma Access, which received coverage from cybersecurity news outlets including CyberSecurityNews and Cryptika. Social media activity was limited, with mentions on Mastodon and Nitter. No significant researcher commentary or controversy was noted beyond standard patch reporting (Palo Alto Advisory).

Recursos adicionales


FuenteEste informe se generó utilizando IA

Relacionado PAN-OS Vulnerabilidades:

CVE ID

Severidad

Puntuación

Tecnologías

Nombre del componente

Exploit de CISA KEV

Tiene arreglo

Fecha de publicación

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoJul 09, 2026
CVE-2026-0301LOW1.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoAug 13, 2026

Evaluación gratuita de vulnerabilidades

Compare su postura de seguridad en la nube

Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.

Solicitar evaluación

Recursos adicionales de Wiz

Obtén una demostración personalizada

¿Listo para ver a Wiz en acción?

"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
David EstlickCISO
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
Adam FletcherJefe de Seguridad
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."
Greg PoniatowskiJefe de Gestión de Amenazas y Vulnerabilidades