PAN-OS: Information Disclosure Vulnerability in Management Web Interface

MonitorCVSS 5.9CVE-2026-0281Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

An information disclosure vulnerability in PAN-OS management web interface allows an unauthenticated attacker with network access to harvest web session tokens if a legitimate user clicks on a malicious link. This affects PAN-OS versions below 12.1.8 on PA-Series and VM-Series firewalls and Panorama, and Prisma Access versions below 11.2.13. Cloud NGFW is not affected. The vulnerability is mitigated by restricting management interface access to trusted internal IP addresses.

What this means
What could happen
An attacker could steal web session tokens from your firewall's management interface if a legitimate administrator clicks a malicious link, potentially allowing unauthorized access to firewall configuration and policy changes.
Who's at risk
This affects organizations running Palo Alto Networks PAN-OS firewalls (PA-Series, VM-Series, Panorama) and Prisma Access deployments. Utilities and water authorities using these devices for network security should evaluate their exposure, particularly if management interfaces are accessible from external networks or untrusted segments.
How it could be exploited
An attacker sends a malicious link to a legitimate administrator with network access to the PAN-OS management web interface. When the administrator clicks the link, the vulnerability allows the attacker to harvest the administrator's web session token without authentication. The attacker can then use that token to access the firewall management interface as if they were the administrator.
Prerequisites
  • Network access to the PAN-OS management web interface
  • A legitimate administrator must click on an attacker-provided malicious link
remotely exploitablerequires user interaction (click malicious link)affects security device management interface
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict management web interface access to only trusted internal IP addresses using firewall rules or network ACLs
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.8 or later
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.13 or later
API: /api/v1/advisories/fe678671-2fae-4417-9162-5641f237f516

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

PAN-OS: Information Disclosure Vulnerability in Management Web Interface | CVSS 5.9 - OTPulse