CVE 9.3 CRITICAL

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal_CVE-2026-0300

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red

Description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.

Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

AI Analysis

Unauthenticated buffer overflow vulnerability in User-ID Authentication Portal

Basic Information

ID CVE-2026-0300
Source palo_alto
Published May 6, 2026 at 18:57
Modified May 6, 2026 at 19:24

Affected Product

Vendor Palo Alto Networks
Product PAN-OS
Version All
Affected Versions Palo Alto Networks PAN-OS 12.1.0
Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Palo Alto Networks
Product PAN-OS
Version 10.2.0, 11.1.0, 11.2.0, 12.1.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.