CVE-2026-0301
PAN-OS vulnerability analysis and mitigation

Overview

CVE-2026-0301 is an information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software that enables an unauthenticated user with network access to obtain sensitive information. It was published on August 12, 2026, and was discovered externally by researcher Jan Breig. Affected products include PAN-OS 10.2.x (before 10.2.8), PAN-OS 11.1.x (before 11.1.16-h1), Cloud NGFW (all versions on AWS and Azure unless running 11.2+), and Prisma Access 10.2.x (before 10.2.10); PAN-OS 11.2, 12.1, and Panorama are not affected. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 1.7 (Low) reflecting exploit maturity and environmental factors (Palo Alto Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-908 (Use of Uninitialized Resource), associated with CAPEC-37 (Retrieve Embedded Sensitive Data). The flaw exists specifically in the URL Filtering feature when a customized response page is configured — if a firewall has imported a custom URL Filtering HTML response page (configurable under Device > Response Pages), uninitialized resource data may be exposed in the response page content served to users. An unauthenticated attacker with network access can trigger this condition by interacting with the URL filtering response mechanism, potentially retrieving sensitive information embedded in the uninitialized resource. The vulnerability does not require privileges or user interaction, but does require the specific configuration of a customized URL filtering response page to be exploitable (Palo Alto Advisory).

Impact

Successful exploitation results in a confidentiality impact — an unauthenticated network-adjacent attacker can obtain sensitive information exposed through the URL filtering response page mechanism. There is no integrity or availability impact. The scope of exposed data is limited to what may be present in uninitialized memory surfaced via the response page variables, and the vulnerability does not enable lateral movement or code execution. For Prisma Access, the risk is further reduced as exploitation requires an authenticated user and management interface access is restricted (Palo Alto Advisory, Github Advisory).

Exploitability

As of the advisory publication date, Palo Alto Networks is not aware of any malicious exploitation of this issue in the wild, and no public proof-of-concept exploit exists. The EPSS score is approximately 0.313% (24th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and exploit maturity is rated as "Unreported" by the vendor. Exploitation is not automatable and requires the specific precondition of a customized URL filtering response page being configured (Palo Alto Advisory, Github Advisory).

Mitigation and workarounds

Palo Alto Networks has released fixed versions: PAN-OS 10.2.8 or later, PAN-OS 11.1.16-h1 or later, and Prisma Access 10.2.10 or later. PAN-OS 11.2 and 12.1 require no action. Cloud NGFW customers will be upgraded during the next scheduled maintenance cycle; those requiring earlier upgrades should contact Palo Alto Networks Support. As a configuration-based workaround, administrators can limit the Response Page Variables on their custom response page to only those included in the predefined URL Filtering Response Pages (user, url, category, pan_form), which are not impacted by this vulnerability. Administrators should verify exposure by navigating to Device > Response Pages and checking whether a custom URL Filtering HTML response page has been imported (Palo Alto Advisory).

Community reactions

The vulnerability was part of a broader August 2026 Palo Alto Networks patch release addressing 11 vulnerabilities across PAN-OS, GlobalProtect, and Prisma Access, which received coverage from cybersecurity news outlets including CyberSecurityNews and Cryptika. Social media activity was limited, with mentions on Mastodon and Nitter. No significant researcher commentary or controversy was noted beyond standard patch reporting (Palo Alto Advisory).

Additional resources


SourceThis report was generated using AI

Related PAN-OS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0301LOW1.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management