HIGH 7.1

CVE-2026-0281: Palo Alto Networks PAN-OS Session Token Disclosure Vulnerability

An unauthenticated attacker can trick a legitimate user into clicking a malicious link that allows the attacker to steal their web session token for the Palo Alto Networks firewall management interface. This token grants access to sensitive firewall configuration and monitoring capabilities. The attack requires both network access to the management interface and social engineering to get a user to click the link, but once successful, the attacker can impersonate that user without needing their password.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.1 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Weaknesses (CWE)
CWE-524
Affected products
1 configuration(s)
Published / Modified
2026-07-09 / 2026-08-11

NVD description (verbatim)

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability.

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-0281 is an information disclosure vulnerability (CWE-524) affecting Palo Alto Networks PAN-OS that allows unauthenticated attackers to obtain valid web session tokens via a clickjacking or similar user-interaction attack vector. The vulnerability exists in the management web interface and can be exploited by an attacker with network access to that interface. The CVSS 3.1 score of 7.1 (HIGH) reflects the combination of network accessibility and no authentication requirement, partially mitigated by the requirement for user interaction. Confidentiality impact is high due to token disclosure; integrity impact is low.

Business impact

Successful exploitation could allow an attacker to assume a legitimate administrator's identity within the firewall management console, potentially leading to unauthorized configuration changes, policy modifications, monitoring bypass, or exfiltration of firewall logs and security data. The actual blast radius depends on the privileges of the compromised user and whether management access is properly segmented from untrusted networks.

Affected systems

This vulnerability affects PAN-OS running on PA-Series and VM-Series firewalls, as well as Panorama deployments (both virtual and M-Series). Cloud NGFW and Prisma Access are not affected. Organizations running any affected PAN-OS version on these platforms should assess their exposure based on their management interface access controls.

Exploitability

Exploitation requires an attacker to have network-layer access to the management web interface—not typically exposed to the internet in properly configured deployments—and to successfully social-engineer a legitimate user into clicking a malicious link. While the technical bar for execution is low once these conditions are met, the practical attack complexity is elevated by the need for user interaction and restricted network access. No public exploit code has been flagged in the known exploited vulnerabilities catalog.

Remediation

Apply the security updates released by Palo Alto Networks for affected PAN-OS versions. As an immediate compensating control, enforce Palo Alto Networks' documented best practice of restricting management web interface access to trusted internal IP addresses only, using network-level controls such as management interface IP whitelisting. Implement multi-factor authentication for management console access where available to reduce the impact of token compromise.

Patch guidance

Consult the official Palo Alto Networks security advisory for CVE-2026-0281 to identify the fixed PAN-OS versions for your specific platform (PA-Series, VM-Series, or Panorama). Apply patches in a change-controlled manner, prioritizing systems with internet-facing or less-restricted management access. Verify the patch version against the vendor advisory before deployment.

Detection guidance

Monitor for unusual session token generation or usage patterns in firewall management logs, particularly tokens created during or shortly after user interaction events. Look for administrative console access from unexpected IP addresses or user agents that differ from normal patterns. Implement logging and alerting on failed management login attempts. Review management interface access logs for evidence of token reuse or impersonation.

Why prioritize this

While this vulnerability carries a HIGH CVSS score and affects critical infrastructure control planes, real-world risk is substantially lower in properly configured environments where management interfaces are restricted to trusted networks. Organizations with exposed or insufficiently segmented management access should prioritize remediation. Those following Palo Alto's own deployment best practices (management access restriction) face lower immediate risk but should still patch as part of normal change management to eliminate the attack vector entirely.

Risk score, explained

The CVSS 3.1 score of 7.1 reflects high confidentiality impact from token disclosure, combined with network accessibility and no authentication requirement. The score is not higher because exploitation requires user interaction (clicking a link) and the attack surface is typically limited to trusted networks in well-designed deployments. Integrity impact is marked as low because token compromise allows session hijacking but does not directly enable arbitrary code execution or persistent backdoor creation.

Frequently asked questions

What happens if an attacker obtains my management console session token?

The attacker can use that token to impersonate your user session without needing your password. They would gain all the permissions you have within the firewall management console, potentially allowing configuration changes, rule modifications, log access, or policy adjustments depending on your user role.

Is this vulnerability exploitable over the internet?

Exploitation requires network access to the management web interface itself. In properly configured deployments where the management interface is restricted to trusted internal networks only, the practical exploit surface is much smaller. However, if your management interface is exposed to untrusted networks, the risk is significantly higher.

Do I need to patch if I have already restricted management access to trusted IPs?

Restricting management access is a strong compensating control, but it does not eliminate the vulnerability entirely. Insider threats or compromised internal systems could still pose a risk. Patching remains the proper remediation and should be included in your regular maintenance cycle.

Are Cloud NGFW and Prisma Access affected?

No. According to the vendor advisory, only PAN-OS on PA-Series, VM-Series, and Panorama platforms are affected. Cloud NGFW and Prisma Access deployments are not vulnerable to this issue.

This analysis is provided for informational purposes and based on official vendor disclosures and CVSS metrics. No exploit code has been observed in active use as of the publication date. Organizations should verify patch availability and compatibility with their specific PAN-OS versions against the official Palo Alto Networks security advisory before deployment. This summary does not constitute formal security advice or risk assessment for your specific environment. Always consult your internal security team and the vendor documentation for definitive guidance on remediation timelines and priorities. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).