9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red
Description
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
AI Analysis
Unauthenticated buffer overflow vulnerability in User-ID Authentication Portal
Basic Information
ID
CVE-2026-0300
Source
palo_alto
Published
May 6, 2026 at 18:57
Modified
May 6, 2026 at 19:24
Affected Product
Vendor
Palo Alto Networks
Product
PAN-OS
Version
All
Affected Versions
Palo Alto Networks PAN-OS 12.1.0
Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0
Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Palo Alto Networks
Product
PAN-OS
Version
10.2.0, 11.1.0, 11.2.0, 12.1.0