CVE-2026-0257: PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities (Severity: HIGH)
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Other sources
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7Fixed in 12.1.4-h6Fixed in 11.2.12Fixed in 11.2.10-h7Fixed in 11.2.7-h14Fixed in 11.2.4-h17Fixed in 11.1.15Fixed in 11.1.13-h5Fixed in 11.1.10-h25Fixed in 11.1.7-h6Fixed in 11.1.6-h32Fixed in 11.1.4-h33Fixed in 10.2.18-h6Fixed in 10.2.16-h7Fixed in 10.2.13-h21Fixed in 10.2.10-h36Fixed in 10.2.7-h34 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.10-h36Fixed in 11.2.7-h13 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 10.2.7-h34 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 10.2.18-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 10.2.13-h21 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 10.2.16-h7 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 10.2.10-h36 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.1.4-h33 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.1.13-h5 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.1.6-h32 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.1.7-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.1.10-h25 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.2.4-h17 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.2.7-h14 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 11.2.10-h7 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 12.1.4-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 12.1.7 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 10.2.18 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (GlobalProtect portal/gateway)to a version that resolves this vulnerability.Fixed in 12.1.5 - Configuration
In the GlobalProtect portal and gateway configuration, disable the “Authentication Override” options used for generating and accepting cookies by unchecking them.
GlobalProtect portal and gateway (PAN-OS) Authentication Override options (generating and accepting cookies) = Unchecked/disabled - Configuration
Use a dedicated certificate exclusively for Authentication Override cookies; generate a new certificate for authentication override cookies and store it securely, and do not reuse/share it with other features or users.
GlobalProtect authentication override cookies (certificate) Certificate reuse/sharing = Do not reuse / do not share - Compensating control
Do not reuse the portal/gateway authentication override cookie certificate and do not share it with other features or users; after upgrade, the firewall will regenerate the authentication override cookie using a more secure method.
- Operational
After upgrading PAN-OS, require GP users to re-authenticate once (one-time requirement), even if an authentication override cookie is present.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0257?
CVE-2026-0257 has been classified with a severity level of MEDIUM.
What does CVE-2026-0257 exploit?
CVE-2026-0257 exploits authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software.
How do I fix CVE-2026-0257?
Fixing CVE-2026-0257 involves upgrading to the latest version of PAN-OS provided by Palo Alto Networks.
Who is affected by CVE-2026-0257?
CVE-2026-0257 affects users of Palo Alto Networks PAN-OS with GlobalProtect functionality.
What can attackers achieve with CVE-2026-0257?
Attackers can establish unauthorized VPN connections by exploiting the vulnerabilities outlined in CVE-2026-0257.