Executive brief
Palo Alto Networks WildFire appliances, which are used for on-premise malware sandboxing and analysis, contain a vulnerability that allows users to read or delete files they should not have access to. An attacker with low-level access to the appliance could steal sensitive information or disrupt operations by deleting critical system files. This issue only affects physical appliances in their default configuration and does not impact the WildFire public cloud service.
Technical details
An arbitrary file read and delete vulnerability (CWE-73 / CAPEC-597) exists in Palo Alto Networks WildFire WF-500 and WF-500-B appliances. The flaw is rooted in improper external control of file names or paths, allowing for absolute path traversal. An attacker with network access and low-level user privileges can exploit this to read sensitive system information or delete arbitrary files on the appliance. The vulnerability specifically affects appliances running in the default non-FIPS configuration mode. Software updates have been released across multiple PAN-OS branches (10.2, 11.1, 11.2, and 12.1) to remediate the issue.
Affected products
- Palo Alto Networks WildFire WF-500 10.2.0 < 10.2.18-h6, 11.1.0 < 11.1.15, 11.2.0 < 11.2.12, 12.1.0 < 12.1.7
- Palo Alto Networks WildFire WF-500-B 10.2.0 < 10.2.18-h6, 11.1.0 < 11.1.15, 11.2.0 < 11.2.12, 12.1.0 < 12.1.7
Timeline
- 2026-05-13: advisory: Initial publication by Palo Alto Networks
- 2026-05-28: patched: Final update to fix release timeline for various versions