4.7
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber
Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Panorama and Cloud NGFW are not impacted by these issues.
Basic Information
ID
CVE-2026-0257
Source
palo_alto
Published
May 13, 2026 at 18:15
Modified
May 13, 2026 at 18:59
Affected Product
Vendor
Palo Alto Networks
Product
Cloud NGFW
Version
All
Affected Versions
Palo Alto Networks PAN-OS 12.1.0
Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0
Palo Alto Networks Prisma Access 10.2.0
Palo Alto Networks Prisma Access 11.2.0
Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0
Palo Alto Networks Prisma Access 10.2.0
Palo Alto Networks Prisma Access 11.2.0