PAN-OS URL Filtering Info Disclosure CVE-2026-0301
CVE-2026-0301 Published on August 13, 2026
PAN-OS: Information Disclosure Vulnerability in URL Filtering
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
Vulnerability Analysis
CVE-2026-0301 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Timeline
Initial publication
Weakness Type
Use of Uninitialized Resource
The software uses or accesses a resource that has not been initialized. When a resource has not been properly initialized, the software may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the software.
Products Associated with CVE-2026-0301
Want to know whenever a new CVE is published for Palo Alto Networks products? stack.watch will email you.
Affected Versions
Palo Alto Networks Cloud NGFW:- Version All is affected.
- Version 12.1.0 is unaffected.
- Version 11.2.0 is unaffected.
- Version 11.1.0 and below 11.1.17 is affected.
- Version 10.2.0 and below 10.2.8 is affected.
- Version 12.1.0 is unaffected.
- Version 11.2.0 is unaffected.
- Version 10.2.0 and below 10.2.10 is affected.