{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-0259", "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0", "state": "PUBLISHED", "assignerShortName": "palo_alto", "dateReserved": "2025-11-03T20:44:19.922Z", "datePublished": "2026-05-13T18:05:45.862Z", "dateUpdated": "2026-05-13T18:57:18.638Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0", "shortName": "palo_alto", "dateUpdated": "2026-05-13T18:05:45.862Z" }, "title": "WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)", "datePublic": "2026-05-13T16:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-73", "description": "CWE-73 External Control of File Name or Path", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-597", "descriptions": [ { "lang": "en", "value": "CAPEC-597 Absolute Path Traversal" } ] } ], "affected": [ { "vendor": "Palo Alto Networks", "product": "WildFire WF-500 and WF-500-B", "versions": [ { "status": "affected", "version": "12.1.0", "lessThan": "12.1.7, 12.1.4-h5", "changes": [ { "at": "12.1.7", "status": "unaffected" }, { "at": "12.1.4-h5", "status": "unaffected" } ], "versionType": "custom" }, { "status": "affected", "version": "11.2.0", "lessThan": "11.2.11,11.2.7-h7", "changes": [ { "at": "11.2.12", "status": "unaffected" }, { "at": "11.2.10-h6", "status": "unaffected" }, { "at": "11.2.7-h13", "status": "unaffected" }, { "at": "11.2.4-h17", "status": "unaffected" } ], "versionType": "custom" }, { "status": "affected", "version": "11.1.0", "lessThan": "11.1.13,11.1.10-h8", "changes": [ { "at": "11.1.15", "status": "unaffected" }, { "at": "11.1.13-h5", "status": "unaffected" }, { "at": "11.1.10-h25", "status": "unaffected" }, { "at": "11.1.7-h6", "status": "unaffected" }, { "at": "11.1.6-h32", "status": "unaffected" }, { "at": "11.1.4-h33", "status": "unaffected" } ], "versionType": "custom" }, { "status": "affected", "version": "10.2.0", "lessThan": "10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34", "changes": [ { "at": "10.2.18-h6", "status": "unaffected" }, { "at": "10.2.16-h7", "status": "unaffected" }, { "at": "10.2.13-h21", "status": "unaffected" }, { "at": "10.2.10-h36", "status": "unaffected" }, { "at": "10.2.7-h34", "status": "unaffected" } ], "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "cpeApplicability": [ { "operator": "OR", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:palo_alto_networks:wildfire_wf-500_and_wf-500-b:*:*:*:*:*:*:*:*", "versionStartIncluding": "12.1.0", "versionEndExcluding": "12.1.7_12.1.4-h5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:palo_alto_networks:wildfire_wf-500_and_wf-500-b:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.2.0", "versionEndExcluding": "11.2.11_11.2.7-h7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:palo_alto_networks:wildfire_wf-500_and_wf-500-b:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.1.0", "versionEndExcluding": "11.1.13_11.1.10-h8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:palo_alto_networks:wildfire_wf-500_and_wf-500-b:*:*:*:*:*:*:*:*", "versionStartIncluding": "10.2.0", "versionEndExcluding": "10.2.18-h6_10.2.16-h7_10.2.13-h21_10.2.10-h36_10.2.7-h34" } ] } ] } ], "descriptions": [ { "lang": "en", "value": "An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.\n\n\n\nThe WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.\n\n\n\nPlease note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.
The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.
Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.
For airgapped deployments, we strongly recommend that you secure WildFire 500 appliances by restricting access to only trusted internal IP addresses.
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510010 (Applications and Threats content version 9100-10044 and later).
Please note that this Threat ID requires SSL Decryption.
" } ] } ], "solutions": [ { "lang": "eng", "value": "VERSION MINOR VERSION RANGE SUGGESTED SOLUTION\nWildFire WF-500 and WF-500-B 12.1 12.1.5 through 12.1.6 Upgrade to 12.1.7 or later.\n 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h5 or 12.1.7 or later.\nWildFire WF-500 and WF-500-B 11.2 11.2.11 or later Upgrade to 11.2.12 or later.\n 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h6 or 11.2.12 or later.\n 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h13 or 11.2.12 or later.\n 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h17 or 11.2.12 or later.\nWildFire WF-500 and WF-500-B 11.1 11.1.14 or later Upgrade to 11.1.15 or later.\n 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h5 or 11.1.15 or later.\n 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h25 or 11.1.15 or later.\n 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h6 or 11.1.15 or later.\n 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h32 or 11.1.15 or later.\n 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h33 or 11.1.15 or later.\nWildFire WF-500 and WF-500-B 10.2 10.2.17 through 10.2.18-h* Upgrade to 10.2.18-h6 or later.\n 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h7 or 10.2.18-h6 or later.\n 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h21 or 10.2.18-h6 or later.\n 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h36 or 10.2.18-h6 or later.\n 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h34 or 10.2.18-h6 or later.\nWildFire WF-500 and WF-500-B 10.1 All (EoL) No fix planned. Upgrade to a supported version.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "| Version | Minor Version Range | Suggested Solution |
|---|---|---|
| WildFire WF-500 and WF-500-B 12.1 | 12.1.5 through 12.1.6 | Upgrade to 12.1.7 or later. |
| 12.1.2 through 12.1.4-h* | Upgrade to 12.1.4-h5 or 12.1.7 or later. | |
| WildFire WF-500 and WF-500-B 11.2 | 11.2.11 or later | Upgrade to 11.2.12 or later. |
| 11.2.8 through 11.2.10-h* | Upgrade to 11.2.10-h6 or 11.2.12 or later. | |
| 11.2.5 through 11.2.7-h* | Upgrade to 11.2.7-h13 or 11.2.12 or later. | |
| 11.2.0 through 11.2.4-h* | Upgrade to 11.2.4-h17 or 11.2.12 or later. | |
| WildFire WF-500 and WF-500-B 11.1 | 11.1.14 or later | Upgrade to 11.1.15 or later. |
| 11.1.11 through 11.1.13-h* | Upgrade to 11.1.13-h5 or 11.1.15 or later. | |
| 11.1.8 through 11.1.10-h* | Upgrade to 11.1.10-h25 or 11.1.15 or later. | |
| 11.1.7 through 11.1.7-h* | Upgrade to 11.1.7-h6 or 11.1.15 or later. | |
| 11.1.5 through 11.1.6-h* | Upgrade to 11.1.6-h32 or 11.1.15 or later. | |
| 11.1.0 through 11.1.4-h* | Upgrade to 11.1.4-h33 or 11.1.15 or later. | |
| WildFire WF-500 and WF-500-B 10.2 | 10.2.17 through 10.2.18-h* | Upgrade to 10.2.18-h6 or later. |
| 10.2.14 through 10.2.16-h* | Upgrade to 10.2.16-h7 or 10.2.18-h6 or later. | |
| 10.2.11 through 10.2.13-h* | Upgrade to 10.2.13-h21 or 10.2.18-h6 or later. | |
| 10.2.8 through 10.2.10-h* | Upgrade to 10.2.10-h36 or 10.2.18-h6 or later. | |
| 10.2.0 through 10.2.7-h* | Upgrade to 10.2.7-h34 or 10.2.18-h6 or later. | |
| WildFire WF-500 and WF-500-B 10.1 | All (EoL) | No fix planned. Upgrade to a supported version. |
Palo Alto Networks is not aware of any malicious exploitation of this issue.
" } ] } ], "timeline": [ { "time": "2026-05-13T16:00:00.000Z", "lang": "en", "value": "Initial publication." } ], "credits": [ { "lang": "en", "value": "Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.", "type": "other" } ], "source": { "discovery": "INTERNAL" }, "x_generator": { "engine": "Vulnogram 0.1.0-dev" }, "x_affectedList": [ "WildFire WF-500 and WF-500-B 12.1.0", "WildFire WF-500 and WF-500-B 12.1.1", "WildFire WF-500 and WF-500-B 12.1.2", "WildFire WF-500 and WF-500-B 12.1.3", "WildFire WF-500 and WF-500-B 11.2.0", "WildFire WF-500 and WF-500-B 11.2.1", "WildFire WF-500 and WF-500-B 11.2.2", "WildFire WF-500 and WF-500-B 11.2.3", "WildFire WF-500 and WF-500-B 11.1.0", "WildFire WF-500 and WF-500-B 11.1.1", "WildFire WF-500 and WF-500-B 11.1.2", "WildFire WF-500 and WF-500-B 11.1.3", "WildFire WF-500 and WF-500-B 10.2.0", "WildFire WF-500 and WF-500-B 10.2.1", "WildFire WF-500 and WF-500-B 10.2.2", "WildFire WF-500 and WF-500-B 10.2.3", "WildFire WF-500 and WF-500-B 10.2.4", "WildFire WF-500 and WF-500-B 10.2.5", "WildFire WF-500 and WF-500-B 10.2.6" ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-13T18:56:39.294156Z", "id": "CVE-2026-0259", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-13T18:57:18.638Z" } } ] } }