Search

Vulnerability in Palo Alto PAN-OS (CVE-2026-0301)

PAN-OS is the next generation firewall software of Palo Alto.

CVE-2026-0301: Information disclosure vulnerability in Palo Alto PAN-OS

Palo Alto PAN-OS 11.1.8 contains an information disclosure vulnerability that affects instances with a customized response page where URL filtering is enabled. The vulnerability allows an attacker to display data of random memory locations over the block page by repeatedly querying websites that are blocked by the firewall. Furthermore, the vulnerability allows an attacker to write to a fixed offset in memory by manipulating the URL query string, so that the input is reflected on the block page.

The vulnerability was acknowledged and completely fixed by Palo Alto within 369 days.

CVSS Score
6.3 (CVSS v4) 

CVSS Vector String
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
/E:U/AU:N/R:U/V:D/RE:M/U:Amber

CVSS vector string (cirosec):
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N

Affected Version
PAN-OS < 10.2.8, PAN-OS < 11.1.16-h1, Prisma Access < 10.2.10

Fixed Version
PAN-OS >= 10.2.8, PAN-OS >= 11.1.16-h1, Prisma Access >= 10.2.10

References
https://security.paloaltonetworks.com/CVE-2026-0301

Credits
Jan Breig (cirosec GmbH)

Timeline

Do you want to protect your systems? Feel free to get in touch with us.
Search
Search