PAN-OS: Information Disclosure Vulnerability in URL Filtering
- Sévérité
- Élevée7,5CVSS 3.1, Élevée
- EPSS
- 0,32 %
- Publiée
- 13 août 2026
- Mise à jour
- 28 août 2026
Description
Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
Faiblesse : CWE-908
Exploitée activement
Non listée dans CISA KEV lors de la dernière vérification.
Prédiction d’exploitation
Probabilité d’exploitation de 0,32 % dans les 30 prochains jours (percentile 22 %).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ce qu’indique la source, par branche
Versions comparées par Patcharo
Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)
| Branche | Affectées | Corrigé en |
|---|---|---|
| 11.1 | >= 11.1.0, < 11.1.16-h1 | 11.1.16-h1 |
| 10.2 | >= 10.2.0, < 10.2.8 | 10.2.8 |
Selon l’éditeur, les versions non listées ne sont pas affectées.
Produits concernés
- Palo Alto Networks Cloud NGFW · All
- Palo Alto Networks Prisma Access · 10.2.0 < 10.2.10
Contournement / Remédiation de l’éditeur
Contournement · PAN-OS
Customers can mitigate this issue by limiting the Response Page Variables https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44 on their response page to only those in the Predefined URL Filtering Response Pages https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f . https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f The variables that are included in our predefined response pages (user, url, category, pan_form…
Remédiation de l’éditeur · PAN-OS
Version Minor Version Suggested Solution Cloud NGFW*Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.PAN-OS 12.1 12.1.2 through 12.1.6-h*No action needed.PAN-OS 11.2 11.2.0 through 11.2.12 No action needed. PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or later. PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.16-h1 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access 12.1 12.1.2 through 12.1.* No action needed.Prisma Access 11.2 11.2.0 through 11.2* No action needed. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.
Références
Provenance
Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
- NVD
- NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0
Dernière vérification : 28 sept. 2026, 02:31 UTC