CVE-2024-5916: Palo Alto Networks PAN-OS

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.

Affected products

  • Palo Alto Networks PAN-OS: from 10.2.0, before 10.2.8 (fixed in 10.2.8); from 11.0.0, before 11.0.4 (fixed in 11.0.4)

Published 2024-08-14. Last modified 2026-06-17.