CVE-2026-0301
PAN-OS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-0301 is an information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software that enables an unauthenticated user with network access to obtain sensitive information. It was published on August 12, 2026, and was discovered externally by researcher Jan Breig. Affected products include PAN-OS 10.2.x (before 10.2.8), PAN-OS 11.1.x (before 11.1.16-h1), Cloud NGFW (all versions on AWS and Azure unless running 11.2+), and Prisma Access 10.2.x (before 10.2.10); PAN-OS 11.2, 12.1, and Panorama are not affected. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 1.7 (Low) reflecting exploit maturity and environmental factors (Palo Alto Advisory, Github Advisory).

Détails techniques

The vulnerability is classified as CWE-908 (Use of Uninitialized Resource), associated with CAPEC-37 (Retrieve Embedded Sensitive Data). The flaw exists specifically in the URL Filtering feature when a customized response page is configured — if a firewall has imported a custom URL Filtering HTML response page (configurable under Device > Response Pages), uninitialized resource data may be exposed in the response page content served to users. An unauthenticated attacker with network access can trigger this condition by interacting with the URL filtering response mechanism, potentially retrieving sensitive information embedded in the uninitialized resource. The vulnerability does not require privileges or user interaction, but does require the specific configuration of a customized URL filtering response page to be exploitable (Palo Alto Advisory).

Impact

Successful exploitation results in a confidentiality impact — an unauthenticated network-adjacent attacker can obtain sensitive information exposed through the URL filtering response page mechanism. There is no integrity or availability impact. The scope of exposed data is limited to what may be present in uninitialized memory surfaced via the response page variables, and the vulnerability does not enable lateral movement or code execution. For Prisma Access, the risk is further reduced as exploitation requires an authenticated user and management interface access is restricted (Palo Alto Advisory, Github Advisory).

Exploitabilité

As of the advisory publication date, Palo Alto Networks is not aware of any malicious exploitation of this issue in the wild, and no public proof-of-concept exploit exists. The EPSS score is approximately 0.313% (24th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and exploit maturity is rated as "Unreported" by the vendor. Exploitation is not automatable and requires the specific precondition of a customized URL filtering response page being configured (Palo Alto Advisory, Github Advisory).

Atténuation et solutions de contournement

Palo Alto Networks has released fixed versions: PAN-OS 10.2.8 or later, PAN-OS 11.1.16-h1 or later, and Prisma Access 10.2.10 or later. PAN-OS 11.2 and 12.1 require no action. Cloud NGFW customers will be upgraded during the next scheduled maintenance cycle; those requiring earlier upgrades should contact Palo Alto Networks Support. As a configuration-based workaround, administrators can limit the Response Page Variables on their custom response page to only those included in the predefined URL Filtering Response Pages (user, url, category, pan_form), which are not impacted by this vulnerability. Administrators should verify exposure by navigating to Device > Response Pages and checking whether a custom URL Filtering HTML response page has been imported (Palo Alto Advisory).

Réactions de la communauté

The vulnerability was part of a broader August 2026 Palo Alto Networks patch release addressing 11 vulnerabilities across PAN-OS, GlobalProtect, and Prisma Access, which received coverage from cybersecurity news outlets including CyberSecurityNews and Cryptika. Social media activity was limited, with mentions on Mastodon and Nitter. No significant researcher commentary or controversy was noted beyond standard patch reporting (Palo Alto Advisory).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté PAN-OS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiJul 09, 2026
CVE-2026-0301LOW1.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiAug 13, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités