PAN-OS: Information Disclosure Vulnerability in URL Filtering
- Severity
- High7.5CVSS 3.1, High
- EPSS
- 0.32%
- Published
- 13 Aug 2026
- Updated
- 28 Aug 2026
Description
Title, description and vendor guidance are quoted from the source records.
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
Weakness: CWE-908
Known exploited
Not listed in CISA KEV as of the last check.
Exploit prediction
0.32% probability of exploitation in the next 30 days (percentile 22%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the source states, per branch
Versions matched by Patcharo
Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| 11.1 | >= 11.1.0, < 11.1.16-h1 | 11.1.16-h1 |
| 10.2 | >= 10.2.0, < 10.2.8 | 10.2.8 |
Versions not listed are stated unaffected by the vendor.
Affected products
- Palo Alto Networks Cloud NGFW · All
- Palo Alto Networks Prisma Access · 10.2.0 < 10.2.10
Workaround / Vendor remediation
Workaround · PAN-OS
Customers can mitigate this issue by limiting the Response Page Variables https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44 on their response page to only those in the Predefined URL Filtering Response Pages https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f . https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f The variables that are included in our predefined response pages (user, url, category, pan_form…
Vendor remediation · PAN-OS
Version Minor Version Suggested Solution Cloud NGFW*Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.PAN-OS 12.1 12.1.2 through 12.1.6-h*No action needed.PAN-OS 11.2 11.2.0 through 11.2.12 No action needed. PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or later. PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.16-h1 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access 12.1 12.1.2 through 12.1.* No action needed.Prisma Access 11.2 11.2.0 through 11.2* No action needed. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.
References
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC