CVE-2026-0265
HIGHPalo Alto Networks PAN-OS Unauthenticated Authentication Bypass via Cloud Authentication Service
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2026-0265. PoCs published by SecureWithUmer, BishopFox, tstephens1080.
AI-analyzed exploit summary This Python script detects whether a Palo Alto Networks PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability in the Cloud Authentication Service (CAS). The tool performs a non-intrusive check via a single anonymous GET request to `/global-protect/prelogin.esp` to determine vulnerability status based on CAS attachment and PAN-OS build version.
Description
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Exploits (3)
This Python script detects whether a Palo Alto Networks PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability in the Cloud Authentication Service (CAS). The tool performs a non-intrusive check via a single anonymous GET request to `/global-protect/prelogin.esp` to determine vulnerability status based on CAS attachment and PAN-OS build version.
This repository contains a Python-based scanner tool designed to detect whether a PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265, an authentication bypass vulnerability. The tool performs a single anonymous GET request to `/global-protect/prelogin.esp` to determine if the portal uses Cloud Authentication Service (CAS) and checks the PAN-OS version against the vendor's advisory to assess vulnerability status.
This repository contains a Python script that scans Palo Alto Networks firewalls and Panorama appliances for exposure to CVE-2026-0265, an authentication bypass vulnerability. It checks both the PAN-OS version and whether the Cloud Authentication Service (CAS) is configured, providing a detailed risk assessment.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H