PAN-OS: Information Disclosure Vulnerability in URL Filtering
MonitorCVSS 6.3CVE-2026-0301Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks Cloud NGFW (AWS and Azure deployments) allows an unauthenticated attacker with network access to obtain sensitive information from custom response page variables. The predefined response page variables (user, url, category, pan_form) are not affected. Panorama is not impacted.
What this means
What could happen
An attacker on your network can read sensitive information from URL filtering response pages without authentication, potentially exposing system details or internal data. This affects your network perimeter security posture but does not directly impact process control systems.
Who's at risk
Network security teams using Palo Alto Networks Cloud NGFW on AWS or Azure who have configured custom response page variables in URL filtering. This primarily affects perimeter firewall security but does not directly impact OT/ICS equipment or processes.
How it could be exploited
An attacker with network access to the Cloud NGFW sends requests designed to trigger URL filtering responses. By crafting these requests, the attacker can view custom response page variables that may contain sensitive information (system names, hostnames, internal details) that should not be exposed.
Prerequisites
- Network access to the Cloud NGFW on AWS or Azure
- URL filtering feature enabled with custom response page variables configured
remotely exploitableno authentication requiredno patch availableinformation disclosure
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 pending
ProductAffected VersionsFix Status
Cloud NGFWAll on AWS*No fix yet
Cloud NGFWAll on Azure*No fix yet
Remediation & Mitigation
0/3
Do now
0/2HARDENINGLimit Response Page Variables to only predefined URL Filtering Response Pages (user, url, category, pan_form); remove or disable any custom variables from response pages
HARDENINGAudit current URL filtering response page configurations to identify any custom variables that may expose sensitive information
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Cloud NGFW
HARDENINGReview access logs from your Cloud NGFW to detect any suspicious requests targeting URL filtering responses
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c19b7c26-fb01-49ae-b20c-91d1342fdd8eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.