CVE-2026-0300
CRITICAL KEVPAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Title source: cnaDescription
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Exploits (8)
nomisec
WORKING POC
2 stars
by qassam-315 · poc
https://github.com/qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
nomisec
WORKING POC
1 stars
by p3Nt3st3r-sTAr · poc
https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC
github
NO CODE
1 stars
by Hex0rc1st · pythonpoc
https://github.com/Hex0rc1st/CVE_POC_monitor/tree/main/article/uploads/demo_1778060007/【在野利用】Palo Alto Networks PAN-OS 缓冲区溢出漏洞(CVE-2026-0300)安全风险通告
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300
Vendor Advisory vendor-advisory
https://security.paloaltonetworks.com/CVE-2026-0300
Scores
CVSS v3
9.8
EPSS
0.1490
EPSS Percentile
94.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
yes
Technical Impact
total
Details
CISA KEV
2026-05-06
VulnCheck KEV
2026-05-05
ENISA EUVD
EUVD-2026-27879
CWE
CWE-787
Status
published
Products (20)
Palo Alto Networks/Cloud NGFW
All
Palo Alto Networks/PAN-OS
10.2.0 - 10.2.18-h6
Palo Alto Networks/PAN-OS
11.1.0 - 11.1.15
Palo Alto Networks/PAN-OS
11.2.0 - 11.2.12
Palo Alto Networks/PAN-OS
12.1.0 - 12.1.7
Palo Alto Networks/Prisma Access
All
paloaltonetworks/pan-os
10.2.0
paloaltonetworks/pan-os
10.2.1
paloaltonetworks/pan-os
10.2.2
paloaltonetworks/pan-os
10.2.3
... and 10 more
Published
May 06, 2026
KEV Added
May 06, 2026
Tracked Since
May 07, 2026