Security Advisory Desk
lowQCS priority 56/100Palo Alto Networks

CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)

A security vulnerability in Palo Alto Networks' PAN-OS software can leak sensitive information in the URL filtering feature. This issue affects firewalls using customized response pages for URL filtering, allowing network attackers without login credentials to access confidential data. Palo Alto Networks has released updated software versions to address the problem and offers mitigation advice for users with customized pages.

Published 12/8/2026, 4:00:00 pmVerified 12/8/2026, 9:59:02 pmRevision 1
Palo Alto Networks low network security advisory visual

In plain language

What this advisory means

A security vulnerability in Palo Alto Networks' PAN-OS software can leak sensitive information in the URL filtering feature. This issue affects firewalls using customized response pages for URL filtering, allowing network attackers without login credentials to access confidential data. Palo Alto Networks has released updated software versions to address the problem and offers mitigation advice for users with customized pages.

Technical explanation

How the issue affects the environment

CVE-2026-0301 is an information disclosure vulnerability in the URL Filtering feature of PAN-OS running on certain Palo Alto Networks firewalls. The flaw arises when customized URL Filtering response pages are enabled, permitting unauthenticated attackers with network access to retrieve sensitive information by exploiting uninitialized resource usage (CWE-908). This exposure can occur without user interaction or privileges and is exploitable over the network. Versions prior to 11.1.16-h1, 11.1.17, and 10.2.8 are affected. The issue does not impact Panorama or default response pages. Mitigation includes restricting customized response pages to predefined variables to avoid sensitive data leakage.

Operational impact

Why teams should care

Organizations using affected PAN-OS versions with customized URL Filtering response pages risk unauthorized disclosure of sensitive information, which could lead to increased exposure of internal data. Although the severity is rated low, this vulnerability allows network attackers to access potentially sensitive data without credentials or user interaction, potentially undermining confidentiality and trust in security controls. Prompt updating or mitigation can reduce this risk and help maintain compliance with information security policies.

Immediate action

Customers should upgrade to fixed PAN-OS versions: 11.1.16-h1 or later for 11.1.x releases, and 10.2.8 or later for 10.2.x releases. Prisma Access and Cloud NGFW customers will have automatic upgrades during the next maintenance cycle or may schedule on-demand upgrades through Palo Alto Networks support.

Affected and fixed releases

Affected versionsPAN-OS 11.1.0 through 11.1.16-h, PAN-OS 10.2.0 through 10.2.7, PAN-OS 11.1.16
Fixed versionsPAN-OS 11.1.16-h1, PAN-OS 11.1.17, PAN-OS 10.2.8

Temporary risk reduction

To mitigate exposure, restrict customized URL Filtering response pages to use only predefined variables (user, url, category, pan_form) included in Palo Alto Networks' default response pages. Avoid using imported or customized HTML response pages as these may leak sensitive data.

Evidence and validation checklist

  • https://security.paloaltonetworks.com/CVE-2026-0301
  • CVE identification CVE-2026-0301
  • Description of vulnerability affecting PAN-OS URL Filtering
  • Affected versions and fixed versions listed
  • Mitigation guidance to restrict response page variables
  • Status on exploitation not reported

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source