CVE-2026-0265

HIGH

Palo Alto Networks PAN-OS Unauthenticated Authentication Bypass via Cloud Authentication Service

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-0265. PoCs published by SecureWithUmer, BishopFox, tstephens1080.

AI-analyzed exploit summary This Python script detects whether a Palo Alto Networks PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability in the Cloud Authentication Service (CAS). The tool performs a non-intrusive check via a single anonymous GET request to `/global-protect/prelogin.esp` to determine vulnerability status based on CAS attachment and PAN-OS build version.

Description

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Exploits (3)

github SCANNER
by SecureWithUmer · c++poc
https://github.com/SecureWithUmer/CVE-2026-PoCs/tree/main/2026/CVE-2026-0265

This Python script detects whether a Palo Alto Networks PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability in the Cloud Authentication Service (CAS). The tool performs a non-intrusive check via a single anonymous GET request to `/global-protect/prelogin.esp` to determine vulnerability status based on CAS attachment and PAN-OS build version.

Classification
Scanner 99%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Palo Alto Networks PAN-OS (GlobalProtect portal) with Cloud Authentication Service (CAS) enabled, versions below patched hotfixes per advisory
No auth needed
Prerequisites: Network access to the GlobalProtect portal · CAS configured as the authentication method
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
github SCANNER
by BishopFox · pythonpoc
https://github.com/BishopFox/CVE-2026-0265-check

This repository contains a Python-based scanner tool designed to detect whether a PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability. The tool performs a single anonymous GET request to `/global-protect/prelogin.esp` to determine if the portal uses Cloud Authentication Service (CAS) and checks the PAN-OS version against the vendor's advisory to assess vulnerability status.

Classification
Scanner 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: PAN-OS GlobalProtect portal
No auth needed
Prerequisites: Network access to the GlobalProtect portal · PAN-OS version and CAS configuration exposed via `/global-protect/prelogin.esp`
mistral-large-3 · analyzed May 23, 2026 Full analysis →
nomisec SCANNER
by tstephens1080 · poc
https://github.com/tstephens1080/palo-alto-cve-2026-0265-checker

This repository contains a Python script that scans Palo Alto Networks firewalls and Panorama appliances for exposure to CVE-2026-0265, an authentication bypass vulnerability. It checks both the PAN-OS version and whether the Cloud Authentication Service (CAS) is configured, providing a detailed risk assessment.

Classification
Scanner 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Palo Alto Networks PAN-OS
Auth required
Prerequisites: SSH access to target devices · read-only admin credentials · Python 3.8+ with paramiko
mistral-large-3 · analyzed May 17, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0038
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (8)
Palo Alto Networks/Cloud NGFW All
Palo Alto Networks/PAN-OS 10.2.0 - 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34
Palo Alto Networks/PAN-OS 11.1.0 - 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33
Palo Alto Networks/PAN-OS 11.2.0 - 11.2.12, 11.2.10-h6, 11.2.7-h13, 11.2.4-h17
Palo Alto Networks/PAN-OS 12.1.0 - 12.1.7, 12.1.4-h5
Palo Alto Networks/Prisma Access All
paloaltonetworks/pan-os 10.2.7 (26 CPE variants)
paloaltonetworks/pan-os 10.2.10 (18 CPE variants)
Published May 13, 2026
Tracked Since May 13, 2026