CVE-2026-0300

CRITICAL KEV

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

Title source: cna
STIX 2.1

Description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

Exploits (8)

nomisec WORKING POC 2 stars
by qassam-315 · poc
https://github.com/qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
nomisec WORKING POC 1 stars
by p3Nt3st3r-sTAr · poc
https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC
nomisec WORKING POC 1 stars
by mr-r3b00t · poc
https://github.com/mr-r3b00t/CVE-2026-0300
nomisec SCANNER
by shizuku198411 · poc
https://github.com/shizuku198411/CVE-2026-0300
nomisec WORKING POC
by bannned-bit · poc
https://github.com/bannned-bit/CVE-2026-0300-PANOS
nomisec SCANNER
by TailwindRG · poc
https://github.com/TailwindRG/cve-2026-0300-audit
nomisec SCANNER
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-0300

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://security.paloaltonetworks.com/CVE-2026-0300

Scores

CVSS v3 9.8
EPSS 0.1490
EPSS Percentile 94.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-05-06
VulnCheck KEV 2026-05-05
ENISA EUVD EUVD-2026-27879
CWE
CWE-787
Status published
Products (20)
Palo Alto Networks/Cloud NGFW All
Palo Alto Networks/PAN-OS 10.2.0 - 10.2.18-h6
Palo Alto Networks/PAN-OS 11.1.0 - 11.1.15
Palo Alto Networks/PAN-OS 11.2.0 - 11.2.12
Palo Alto Networks/PAN-OS 12.1.0 - 12.1.7
Palo Alto Networks/Prisma Access All
paloaltonetworks/pan-os 10.2.0
paloaltonetworks/pan-os 10.2.1
paloaltonetworks/pan-os 10.2.2
paloaltonetworks/pan-os 10.2.3
... and 10 more
Published May 06, 2026
KEV Added May 06, 2026
Tracked Since May 07, 2026