CVE-2026-0285: PAN-OS Server-Side Request Forgery (SSRF) – Palo Alto Networks
A vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators with access to the management interface to make unauthorized requests from the firewall itself to internal services. This server-side request forgery (SSRF) flaw could enable an admin to pivot toward backend systems or services that should only be reachable from within the firewall's network. The risk is materially reduced if you follow Palo Alto Networks' recommended practice of restricting management interface access to trusted internal IP addresses only.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.9 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- Weaknesses (CWE)
- CWE-918
- Affected products
- 190 configuration(s)
- Published / Modified
- 2026-07-09 / 2026-08-11
NVD description (verbatim)
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-0285 is a server-side request forgery vulnerability (CWE-918) in PAN-OS that allows an authenticated administrator to forge requests originating from the firewall to internal services. The vulnerability requires network access to the management web interface and high-privilege administrator credentials. The CVSS v3.1 score of 4.9 (MEDIUM) reflects the integrity impact and the privilege requirement—an attacker must already have admin access to the management plane. The vulnerability does not affect Panorama, Cloud NGFW, or Prisma Access platforms.
Business impact
This vulnerability primarily affects organizations running on-premises PAN-OS firewalls with relaxed management interface access controls. An insider threat or compromised admin account could abuse this flaw to probe or attack internal services behind the firewall, potentially leading to lateral movement, data exfiltration, or service disruption. Organizations with strong perimeter controls and restricted management access face lower practical risk. The fact that cloud and Panorama deployments are unaffected limits the blast radius for cloud-centric architectures.
Affected systems
Palo Alto Networks PAN-OS is affected across multiple versions. The vulnerability does not impact Panorama (centralized management), Cloud NGFW, or Prisma Access. Organizations running on-premises PAN-OS firewalls should verify their specific version against Palo Alto Networks' published advisory to determine patching eligibility. Consult the vendor advisory for the complete list of affected and remediated versions.
Exploitability
Exploitation requires an authenticated administrator account with access to the management web interface and network connectivity to that interface. There is no unauthenticated path to exploiting this vulnerability. The moderate CVSS score reflects both the privileged access requirement and the conditional nature of the threat. This is not a critical internet-facing vulnerability, but a lateral-movement risk for organizations where management access controls are weak or where insider threats are a concern.
Remediation
Apply security updates from Palo Alto Networks as specified in their advisory. Simultaneously, implement or enforce Palo Alto Networks' recommended best practice: restrict management interface access to only trusted internal IP addresses via firewall rules or network segmentation. This two-pronged approach—patching plus network isolation—significantly reduces the practical risk and should be prioritized in your remediation plan.
Patch guidance
Consult the Palo Alto Networks security advisory for affected version numbers and corresponding patches. Patches are available and should be applied according to your change management process. Verify the patch version against the official vendor advisory before deployment. Test patches in a non-production environment first, as management interface changes can affect firewall operability if not applied carefully.
Detection guidance
Monitor management interface access logs for unusual administrative activity, particularly authenticated requests that attempt to contact internal services or IP addresses not typically accessed via the management interface. Look for admin accounts making outbound requests to unexpected destinations. Review firewall logs for anomalies in request patterns following the advisory publication date. Network segmentation and access controls reduce the visibility of this activity, so focus on administrative user behavior analytics and management interface audit logs.
Why prioritize this
Although classified as MEDIUM severity, this vulnerability warrants prompt attention because it enables lateral movement from an authenticated management position. Prioritize if: (1) your management interface is exposed to a broad set of administrators or untrusted networks, (2) you lack strong internal network segmentation, or (3) insider threats are a concern in your environment. Organizations with properly isolated management access can safely schedule this in a standard patch cycle but should not deprioritize indefinitely. The fact that it's not yet in CISA's Known Exploited Vulnerabilities catalog suggests active exploitation is not widespread, reducing time-sensitive pressure.
Risk score, explained
The CVSS 3.1 score of 4.9 reflects a MEDIUM severity driven by the integrity impact (the ability to make unauthorized requests) offset by the high privilege requirement (admin access) and lack of user interaction. The attack vector is network (the interface is reachable over the network), but complexity is low and scope is unchanged (the attacker operates within the firewall's security context). The score appropriately captures that this is a serious insider or compromised-credential risk, not a mass-exploitation scenario.
Frequently asked questions
Does this vulnerability allow unauthenticated access to internal services?
No. Exploitation requires an authenticated administrator account with credentials and network access to the PAN-OS management interface. This is not an unauthenticated vulnerability and does not pose a direct internet-facing risk.
Are cloud-based Palo Alto Networks deployments affected?
No. Panorama, Cloud NGFW, and Prisma Access are explicitly not impacted. Only on-premises PAN-OS firewalls are vulnerable.
What is the most effective mitigation short of patching?
Restrict management interface access to only trusted internal IP addresses using firewall rules or network segmentation, per Palo Alto Networks' recommended deployment guidelines. This significantly reduces practical risk while patches are being tested and staged.
Is this vulnerability being actively exploited in the wild?
As of the available data, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, suggesting active, weaponized exploitation is not yet widespread. However, patching should not be delayed indefinitely.
This analysis is based on information available as of the CVE publication date. Patch version numbers, affected product versions, and remediation timelines should be verified against the official Palo Alto Networks security advisory. This assessment does not constitute legal, compliance, or procurement advice. Security teams should validate their specific environment configuration and risk posture before prioritizing remediation. The information provided is for informational purposes and does not guarantee protection against all attack vectors or variants. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2025-36324MEDIUMIBM watsonx.data Intelligence SSRF Vulnerability - Patch & Detection Guide
- CVE-2025-58175MEDIUMGeoServer SSRF Vulnerability in Proxy Configuration
- CVE-2026-10052MEDIUMQuay SSRF in LDAP/SMTP Validation—Internal Network Reconnaissance Risk
- CVE-2026-10177MEDIUMSSRF in Aider-AI Aider 0.86.3 AWS Metadata Endpoint
- CVE-2026-10239MEDIUMJeecgBoot Server-Side Request Forgery (SSRF) in Word Editing Module
- CVE-2026-10240MEDIUMJeecgBoot SSRF Vulnerability in /airag/airagModel/test Endpoint
- CVE-2026-10241MEDIUMJimuReport SSRF in File Download Function – Patch to 3.9.2
- CVE-2026-10274MEDIUMServer-Side Request Forgery in aem-mcp-server