Executive brief
A security vulnerability exists in the management interface of Palo Alto Networks firewalls. An authorized administrator could potentially use this flaw to make unauthorized requests from the firewall to other internal services. This risk is significantly higher if the management interface is exposed to the internet rather than restricted to trusted internal networks.
Technical details
A server-side request forgery (SSRF) vulnerability (CWE-918) exists in the PAN-OS management web interface. The flaw allows an authenticated administrator with network access to the interface to trigger unauthorized requests from the device to internal network services. Exploitation requires high privileges (PR:H) and network reachability to the management port. Palo Alto Networks has released patches for affected versions including 12.1, 11.2, 11.1, and 10.2 branches. Mitigation includes restricting management access to trusted IP addresses or using a jump box.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h8, 12.1.5 < 12.1.7-h2, 11.2 < 11.2.4-h20, 11.2.5 < 11.2.7-h18, 11.2.8 < 11.2.10-h11, 11.2.11 < 11.2.13, 11.1 < 11.1.16, 10.2 < 10.2.18-h8
Timeline
- 2026-07-08: disclosed: Discovered internally by Palo Alto Networks
- 2026-07-08: advisory: Initial advisory published by vendor
- 2026-07-09: other: NVD record created