CVE-2026-0265: PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled.
The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used.
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Other sources
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled.
The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used.
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h5Fixed in 12.1.7Fixed in 11.2.4-h17Fixed in 11.2.7-h13Fixed in 11.2.10-h6Fixed in 11.2.12Fixed in 11.1.4-h33Fixed in 11.1.6-h32Fixed in 11.1.7-h6Fixed in 11.1.10-h25Fixed in 11.1.13-h5Fixed in 11.1.15Fixed in 10.2.7-h34Fixed in 10.2.10-h36Fixed in 10.2.13-h21Fixed in 10.2.16-h7Fixed in 10.2.18-h6 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.7-h34 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.10-h36 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.16-h7 - Upgrade
Upgrade
PAN-OS 10.2to a version that resolves this vulnerability.Fixed in 10.2.18-h6 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.4-h33 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.13-h5 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.6-h32 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.7-h6 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.10-h25 - Upgrade
Upgrade
PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.4-h17 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.7-h13 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.10-h6 - Upgrade
Upgrade
PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.4-h5 - Upgrade
Upgrade
PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.7 - Configuration
Temporarily mitigate the authentication bypass vulnerability by disabling the Cloud Authentication Service (CAS) by changing the associated authentication profile to SAML, RADIUS, or other supported authentication methods.
Cloud Authentication Service (CAS) authentication profile = SAML, RADIUS, or other supported authentication methods (instead of CAS) - Configuration
With a Threat Prevention subscription, block attacks for this vulnerability by enabling Threat ID 510008 from Applications and Threats content version 9100-10044 and later.
Threat Prevention Threat ID = 510008 (Applications and Threats content version 9100-10044 and later) - Configuration
Restrict access to the management interface (management web interface) to only trusted internal IP addresses to prevent external access from the internet.
Management web interface access restriction = Restrict to only trusted internal IP addresses - Compensating control
Decrypt inbound traffic to the management interface so the firewall can inspect it.
- Compensating control
Enable Threat Prevention on the inbound traffic to management services.
- Compensating control
Ensure a vulnerability protection security profile is applied to your GlobalProtect interface.
- Compensating control
Replace the default certificate for Inbound Traffic Management.
- Compensating control
Route incoming traffic for the MGT port through a DP port (e.g., enable the management profile on a DP interface for management access).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0265?
CVE-2026-0265 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-0265?
To remediate CVE-2026-0265, upgrade your Palo Alto Networks PAN-OS to a version that includes the security patches such as 12.1.4-h5 or later.
Which products are affected by CVE-2026-0265?
CVE-2026-0265 affects Palo Alto Networks PAN-OS, Panorama, Prisma Access, and Cloud NGFW when Cloud Authentication Service is enabled.
Can unauthenticated attackers exploit CVE-2026-0265?
Yes, CVE-2026-0265 allows unauthenticated attackers with network access to bypass authentication mechanisms.
Is Cloud Authentication Service related to CVE-2026-0265?
Yes, the vulnerability specifically involves the Cloud Authentication Service (CAS) being enabled within the affected software.