CVE-2026-0265

HIGH

Palo Alto Networks PAN-OS Unauthenticated Authentication Bypass via Cloud Authentication Service

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-0265. PoCs published by BishopFox, tstephens1080.

AI-analyzed exploit summary This repository contains a Python-based scanner tool designed to detect whether a PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability. The tool performs a single anonymous GET request to `/global-protect/prelogin.esp` to determine if the portal uses Cloud Authentication Service (CAS) and checks the PAN-OS version against the vendor's advisory to assess vulnerability status.

Description

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Exploits (2)

github SCANNER
by BishopFox · pythonpoc
https://github.com/BishopFox/CVE-2026-0265-check

This repository contains a Python-based scanner tool designed to detect whether a PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability. The tool performs a single anonymous GET request to `/global-protect/prelogin.esp` to determine if the portal uses Cloud Authentication Service (CAS) and checks the PAN-OS version against the vendor's advisory to assess vulnerability status.

Classification
Scanner 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: PAN-OS GlobalProtect portal
No auth needed
Prerequisites: Network access to the GlobalProtect portal · PAN-OS version and CAS configuration exposed via `/global-protect/prelogin.esp`
devstral-2 · analyzed May 23, 2026 Full analysis →
nomisec SCANNER
by tstephens1080 · poc
https://github.com/tstephens1080/palo-alto-cve-2026-0265-checker

This repository contains a Python script that scans Palo Alto Networks firewalls and Panorama appliances for exposure to CVE-2026-0265, an authentication bypass vulnerability. It checks both the PAN-OS version and whether the Cloud Authentication Service (CAS) is configured, providing a detailed risk assessment.

Classification
Scanner 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Palo Alto Networks PAN-OS
Auth required
Prerequisites: SSH access to target devices · read-only admin credentials · Python 3.8+ with paramiko
devstral-2 · analyzed May 17, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v4 7.2
EPSS 0.0004
EPSS Percentile 13.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (6)
Palo Alto Networks/Cloud NGFW All
Palo Alto Networks/PAN-OS 10.2.0 - 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34
Palo Alto Networks/PAN-OS 11.1.0 - 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33
Palo Alto Networks/PAN-OS 11.2.0 - 11.2.12, 11.2.10-h6, 11.2.7-h13, 11.2.4-h17
Palo Alto Networks/PAN-OS 12.1.0 - 12.1.7, 12.1.4-h5
Palo Alto Networks/Prisma Access All
Published May 13, 2026
Tracked Since May 13, 2026