CVE-2026-0301

EUVD-2026-57714
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
paloaltonetworkscloud_ngfw
-
paloaltonetworkscloud_ngfw
-
paloaltonetworksprisma_access
𝑥
< 6.0.0
paloaltonetworkspan-os
10.2.0 ≤
𝑥
< 10.2.8
paloaltonetworkspan-os
11.1.0 ≤
𝑥
< 11.1.16
paloaltonetworkspan-os
11.1.16
𝑥
= Vulnerable software versions