PAN-OS

CVE-2026-0301: Information Disclosure Vulnerability in URL Filtering

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityLOWCVSS 4.0 6.3
EPSS0.32%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Cloud NGFW (AWS, Azure)See the advisory
PAN-OS 11.2, 12.1Not affected
PAN-OS 11.111.1.16-h1 or later
PAN-OS 10.210.2.8 or later
Prisma Access 11.2, 12.1Not affected
Prisma Access 10.210.2.10 or later

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.

Am I affected?

This issue applies only to firewalls where URL filtering is enabled with customized response page.

To check if a PAN-OS device has Customized URL Filtering response pages, navigate to: Device > Response Pages (https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/launch-the-web-interface/configure-response-pages) https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/launch-the-web-interface/configure-response-pagesIf you have imported a custom URL Filtering HTML response page, your device is affected.

Workarounds

Customers can mitigate this issue by limiting the Response Page Variables (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44) on their response page to only those in the Predefined URL Filtering Response Pages (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f). (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f) The variables that are included in our predefined response pages (user, url, category, pan_form) are not impacted by this vulnerability.

Exploitation

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.