CVE-2026-0259
paloaltonetworks pan-os: External Control of File Name or Path
Affected
- paloaltonetworks/pan-os
lt *..10.2.7 - paloaltonetworks/pan-os
between 10.2.8..10.2.10 - paloaltonetworks/pan-os
between 10.2.11..10.2.13 - paloaltonetworks/pan-os
between 10.2.14..10.2.16 - paloaltonetworks/pan-os
between 11.1.0..11.1.4 - paloaltonetworks/pan-os
between 11.1.5..11.1.6 - paloaltonetworks/pan-os
between 11.1.8..11.1.10 - paloaltonetworks/pan-os
between 11.1.11..11.1.13 - paloaltonetworks/pan-os
between 11.2.0..11.2.4 - paloaltonetworks/pan-os
between 11.2.5..11.2.7 - paloaltonetworks/pan-os
between 11.2.8..11.2.10 - paloaltonetworks/pan-os
between 12.1.0..12.1.4 - paloaltonetworks/pan-os
between 12.1.5..12.1.7
Description
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.
Affected operating systems
other
paloaltonetworks / pan-os10.2.10
other
paloaltonetworks / pan-os10.2.13
other
paloaltonetworks / pan-os10.2.16
other
paloaltonetworks / pan-os10.2.17
other
paloaltonetworks / pan-os10.2.18
other
paloaltonetworks / pan-os10.2.7
other
paloaltonetworks / pan-os11.1.10
other
paloaltonetworks / pan-os11.1.13
other
paloaltonetworks / pan-os11.1.14
other
paloaltonetworks / pan-os11.1.4
other
paloaltonetworks / pan-os11.1.6
other
paloaltonetworks / pan-os11.1.7
other
paloaltonetworks / pan-os11.2.10
other
paloaltonetworks / pan-os11.2.11
other
paloaltonetworks / pan-os11.2.4
other
paloaltonetworks / pan-os11.2.7
other
paloaltonetworks / pan-os12.1.4
other
paloaltonetworks / pan-os
Metrics
Show all metrics
Weakness classes (CWE)
CWE-73Base
External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
cwe.mitre.org →