CVE-2026-0285: PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface (Severity: MEDIUM)
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services.
The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Other sources
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services.
The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8Fixed in 12.1.7-h2Fixed in 12.1.4-h8Fixed in 11.2.13Fixed in 11.2.10-h11Fixed in 11.2.7-h18Fixed in 11.2.4-h20Fixed in 11.1.16Fixed in 11.1.13-h9Fixed in 11.1.10-h30Fixed in 11.1.7-h8Fixed in 11.1.6-h35Fixed in 11.1.4-h35Fixed in 10.2.18-h8Fixed in 10.2.16-h9Fixed in 10.2.13-h23Fixed in 10.2.10-h39Fixed in 10.2.7-h36 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.7-h36 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.13-h23 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.16-h9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.10-h39 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.4-h35 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.13-h9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.6-h35 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.7-h8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.10-h30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.4-h20 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.10-h11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7-h2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.18-h8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.18-h8 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.13 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7-h2 or 12.1.8 or later - Configuration
With a Threat Prevention subscription, enable Threat ID 510030 to block attacks for this SSRF vulnerability (Threat ID requires SSL Decryption).
Palo Alto Networks PAN-OS (Threat Prevention) Threat ID 510030 = enabled - Configuration
Enable threat prevention on the inbound traffic to management services.
Palo Alto Networks (management interface inbound traffic) Threat prevention on inbound traffic to management services = enabled - Configuration
Replace the Certificate for Inbound Traffic Management as part of securing inbound management traffic.
Palo Alto Networks firewall (Certificate for inbound traffic management) Inbound Traffic Management Certificate = replaced - Compensating control
Restrict management web interface access to only trusted internal IP addresses per Palo Alto Networks best practice deployment guidelines to minimize the risk of SSRF exploitation.
- Compensating control
Decrypt inbound traffic to the management interface so the firewall can inspect it (SSL decryption for management access).
- Compensating control
Route incoming traffic for the MGT port through a DP (data-plane) port by enabling a management profile on a DP interface for management access, so the traffic is handled/inspected via DP.
- Compensating control
If management interface access is not already restricted, follow the Palo Alto Networks best practice deployment guidelines (trusted internal IPs only) and secure the management access according to their detailed technical documentation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0285?
The severity of CVE-2026-0285 is high with a score of 7.
What kind of vulnerability is CVE-2026-0285?
CVE-2026-0285 is a server-side request forgery (SSRF) vulnerability.
Who is affected by CVE-2026-0285?
CVE-2026-0285 affects authenticated administrators with network access to the management web interface of Palo Alto Networks PAN-OS.
How do I fix CVE-2026-0285?
To fix CVE-2026-0285, ensure that you apply the appropriate updates or patches from Palo Alto Networks for your affected PAN-OS version.
What are the risks posed by CVE-2026-0285?
CVE-2026-0285 can allow unauthorized requests from the firewall to internal services, which may lead to sensitive information exposure.