Information Disclosure Vulnerability in PAN-OS URL Filtering
An information disclosure vulnerability (CVE-2026-0301) in Palo Alto Networks PAN-OS URL Filtering allows unauthenticated attackers to access sensitive memory data if custom response pages are enabled.
Palo Alto Networks has disclosed an information disclosure vulnerability (CVE-2026-0301) affecting the URL Filtering feature in PAN-OS. The flaw is rooted in an uninitialized resource usage (CWE-908) when the firewall is configured to display a custom HTML response page to users. An unauthenticated attacker with network access to the device can exploit this by triggering the display of these custom pages, potentially leading to the leakage of sensitive data residing in system memory.
This issue specifically impacts firewalls running affected versions of PAN-OS 10.2, 11.1, and Prisma Access 10.2, provided that a non-standard, custom URL filtering response page has been imported. Predefined (default) response pages are not impacted by this flaw, as they do not utilize the vulnerable variables. Palo Alto Networks has confirmed there is no evidence of active exploitation in the wild as of August 2026.
Impact
Successful exploitation results in the unauthorized disclosure of sensitive information potentially residing in system memory. While the severity is categorized as low, the exposure depends on the configuration of response pages and the sensitivity of data handled by the firewall. Victims include organizations using customized web-blocking interfaces on impacted PAN-OS devices.
Recommendation
- Upgrade PAN-OS and Prisma Access devices to the patched versions specified in the vendor advisory (e.g., 10.2.8, 11.1.16-h1, 11.1.17, or 10.2.10 for Prisma Access).
- Inspect all custom URL Filtering response pages configured via the device management interface (Device > Response Pages).
- Limit the use of Response Page Variables to only those provided in the Predefined URL Filtering Response Pages (user, url, category, pan_form).
- Deploy the vendor-provided patches as the primary remediation step.
Immediate actions
Review Device > Response Pages for custom HTML configurations
Mitigations
Upgrade PAN-OS to patched versions
CVE-2026-0301