Aller au contenu
Toutes les vulnérabilités
CVE-2026-0301

PAN-OS: Information Disclosure Vulnerability in URL Filtering

Sévérité
Élevée7,5CVSS 3.1, Élevée
EPSS
0,32 %
Publiée
13 août 2026
Mise à jour
28 août 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

Faiblesse : CWE-908

Exploitée activement

Non listée dans CISA KEV lors de la dernière vérification.

Prédiction d’exploitation

Probabilité d’exploitation de 0,32 % dans les 30 prochains jours (percentile 22 %).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Ce qu’indique la source, par branche

Versions comparées par Patcharo

Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)

BrancheAffectéesCorrigé en
11.1
>= 11.1.0, < 11.1.16-h1
11.1.16-h1
10.2
>= 10.2.0, < 10.2.8
10.2.8

Selon l’éditeur, les versions non listées ne sont pas affectées.

Produits concernés

  • Palo Alto Networks Cloud NGFW · All
  • Palo Alto Networks Prisma Access · 10.2.0 < 10.2.10

Contournement / Remédiation de l’éditeur

Contournement · PAN-OS

Customers can mitigate this issue by limiting the Response Page Variables https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44 on their response page to only those in the Predefined URL Filtering Response Pages https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f . https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f The variables that are included in our predefined response pages (user, url, category, pan_form…

Remédiation de l’éditeur · PAN-OS

Version Minor Version Suggested Solution Cloud NGFW*Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.PAN-OS 12.1 12.1.2 through 12.1.6-h*No action needed.PAN-OS 11.2 11.2.0 through 11.2.12 No action needed. PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or later. PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.16-h1 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access 12.1 12.1.2 through 12.1.* No action needed.Prisma Access 11.2 11.2.0 through 11.2* No action needed. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC