Information Disclosure in PAN-OS URL Filtering by Palo Alto Networks
CVE-2026-0301

0.5LOW

Key Information:

Vendor
CVE Published:
13 August 2026

Badges

📈 Score: 591👾 Exploit Exists

What is CVE-2026-0301?

CVE-2026-0301 is a critical information disclosure vulnerability present in the URL Filtering feature of Palo Alto Networks' PAN-OS. PAN-OS is an operating system designed to manage security features on Palo Alto Networks' next-generation firewalls. This vulnerability allows an unauthenticated user with network access to retrieve sensitive information that should be protected. The potential exposure of such data can significantly compromise the security posture of an organization, leading to unauthorized access to sensitive information or network resources.

The flaw stems from improper handling of requests within the URL Filtering component, allowing attackers to exploit this weakness without needing any login credentials, making it particularly dangerous. With the increasing prominence of cyber threats, the presence of this vulnerability necessitates immediate attention from organizations utilizing Palo Alto Networks products.

Potential impact of CVE-2026-0301

  1. Unauthorized Access to Sensitive Information: Attackers can exploit this vulnerability to gain access to sensitive data that is not intended for public disclosure, which could lead to data theft and privacy breaches.

  2. Increased Risk of Further Attacks: By obtaining sensitive information, threat actors might leverage this data to launch more sophisticated attacks, including social engineering or targeted phishing campaigns against the organization.

  3. Damage to Organizational Reputation: A successful exploitation can harm an organization’s reputation, resulting in loss of customer trust and potential financial repercussions due to regulatory fines or decreased business opportunities.

Affected Version(s)

Cloud NGFW AWS All

PAN-OS 11.1.0 < 11.1.16-h1

PAN-OS 10.2.0 < 10.2.8

References

CVSS V4

Score:
0.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jan Breig
.