PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

Plan PatchCVSS 7CVE-2026-0285Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A server-side request forgery (SSRF) vulnerability in PAN-OS allows an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. This could allow an attacker with compromised admin credentials to access internal systems or trigger unauthorized actions. The risk is significantly reduced if the management interface is restricted to only trusted internal IP addresses. Panorama, Cloud NGFW, and Prisma Access are not impacted.

What this means
What could happen
An authenticated administrator with access to the PAN-OS management interface could use this vulnerability to make unauthorized requests to internal services on your network, potentially retrieving sensitive data or triggering actions on internal systems that should not be directly accessible to the firewall.
Who's at risk
Palo Alto Networks PAN-OS firewalls and Prisma Access cloud security service are affected. This matters to organizations running Palo Alto firewalls in perimeter or branch office roles where the management interface may be accessible from the network. Panorama and Cloud NGFW products are not affected.
How it could be exploited
An attacker with valid administrator credentials and network access to the PAN-OS management web interface (typically port 443) could craft requests that cause the firewall to make outbound connections to internal services on behalf of the attacker, bypassing normal network access controls.
Prerequisites
  • Valid administrator credentials for the PAN-OS management interface
  • Network access to the management web interface (port 443 or custom port)
  • The management interface must be accessible (not restricted to trusted internal IPs only)
Requires valid administrator credentialsRequires network access to management interfaceLow attack complexity
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (7)
7 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.4-h2011.2.4-h20+
Prisma AccessBelow 11.2.7-h1811.2.7-h18+
Prisma AccessBelow 11.2.10-h1111.2.10-h11+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/5
Do now
0/2
PAN-OS
HARDENINGRestrict PAN-OS management interface access to only trusted internal IP addresses
All products
WORKAROUNDEnable Threat ID 510030 on your firewall (if you have Threat Prevention subscription and Applications and Threats content version 9122-10145 or later) to block attacks targeting this vulnerability
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.4-h8 or later (if running 12.1.4 branch), 12.1.7-h2 or later (if running 12.1.7 branch), or 12.1.8 or later (if running 12.1.8+ branch)
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.4-h20 or later (if running 11.2.4 branch), 11.2.7-h18 or later (if running 11.2.7 branch), or 11.2.10-h11 or later (if running 11.2.10 branch), or 11.2.13 or later (if running 11.2.13+ branch)
Long-term hardening
0/1
HARDENINGReview and confirm that your management interface access follows Palo Alto Networks best practice deployment guidelines, including multi-factor authentication and strong access controls
API: /api/v1/advisories/8eeec10a-f8e5-47b5-80d6-54764a430f8e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface | CVSS 7 - OTPulse