In plain language
What this advisory means
A security vulnerability in Palo Alto Networks' PAN-OS software can leak sensitive information in the URL filtering feature. This issue affects firewalls using customized response pages for URL filtering, allowing network attackers without login credentials to access confidential data. Palo Alto Networks has released updated software versions to address the problem and offers mitigation advice for users with customized pages.
Technical explanation
How the issue affects the environment
CVE-2026-0301 is an information disclosure vulnerability in the URL Filtering feature of PAN-OS running on certain Palo Alto Networks firewalls. The flaw arises when customized URL Filtering response pages are enabled, permitting unauthenticated attackers with network access to retrieve sensitive information by exploiting uninitialized resource usage (CWE-908). This exposure can occur without user interaction or privileges and is exploitable over the network. Versions prior to 11.1.16-h1, 11.1.17, and 10.2.8 are affected. The issue does not impact Panorama or default response pages. Mitigation includes restricting customized response pages to predefined variables to avoid sensitive data leakage.
Operational impact
Why teams should care
Organizations using affected PAN-OS versions with customized URL Filtering response pages risk unauthorized disclosure of sensitive information, which could lead to increased exposure of internal data. Although the severity is rated low, this vulnerability allows network attackers to access potentially sensitive data without credentials or user interaction, potentially undermining confidentiality and trust in security controls. Prompt updating or mitigation can reduce this risk and help maintain compliance with information security policies.
Immediate action
Customers should upgrade to fixed PAN-OS versions: 11.1.16-h1 or later for 11.1.x releases, and 10.2.8 or later for 10.2.x releases. Prisma Access and Cloud NGFW customers will have automatic upgrades during the next maintenance cycle or may schedule on-demand upgrades through Palo Alto Networks support.
Affected and fixed releases
Temporary risk reduction
To mitigate exposure, restrict customized URL Filtering response pages to use only predefined variables (user, url, category, pan_form) included in Palo Alto Networks' default response pages. Avoid using imported or customized HTML response pages as these may leak sensitive data.
Evidence and validation checklist
- https://security.paloaltonetworks.com/CVE-2026-0301
- CVE identification CVE-2026-0301
- Description of vulnerability affecting PAN-OS URL Filtering
- Affected versions and fixed versions listed
- Mitigation guidance to restrict response page variables
- Status on exploitation not reported
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
