Executive brief
An information disclosure vulnerability exists in the management interface of Palo Alto Networks firewalls and Panorama management servers. If an administrator clicks on a malicious link while their management session is active, an attacker could steal their session token. This could allow the attacker to gain unauthorized access to the device management console, potentially leading to configuration changes or further network compromise.
Technical details
An information disclosure vulnerability (CWE-524) exists in the PAN-OS management web interface due to improper handling of sensitive information in the cache. An unauthenticated attacker with network access to the management interface can obtain web session tokens, provided they can induce a legitimate user to interact with a malicious link (User Interaction: Active). This vulnerability affects PA-Series, VM-Series, and Panorama appliances. Successful exploitation allows for session hijacking. Palo Alto Networks has released patches in versions 12.1.8, 11.2.13, and 11.1.16; users on 10.2 must upgrade to a fixed higher branch. Mitigation includes restricting management interface access to trusted internal IP addresses.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.8, 11.2 < 11.2.13, 11.1 < 11.1.16, 10.2 All versions
- Palo Alto Networks Panorama All versions running affected PAN-OS releases
Timeline
- 2026-07-08: disclosed: Discovered internally by Palo Alto Networks research teams.
- 2026-07-08: advisory: Initial publication of the security advisory.