PT-2026-56910 · Palo Alto Networks · Pan-Os
CVE-2026-0281
·
Published
2026-07-08
·
Updated
2026-07-09
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PAN-OS (affected versions not specified)
Description
An information disclosure issue in the management web interface allows an unauthenticated attacker with network access to obtain web session tokens. This occurs through caching and requires a legitimate user to click a malicious link provided by the attacker.
Recommendations
Restrict access to the management web interface to trusted internal IP addresses.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os