CVE-2026-0300: PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC) by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Other sources
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
— MITRE
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7Fixed in 12.1.4-h5Fixed in 11.2.12Fixed in 11.2.10-h6Fixed in 11.2.7-h13Fixed in 11.2.4-h17Fixed in 11.1.15Fixed in 11.1.13-h5Fixed in 11.1.10-h25Fixed in 11.1.7-h6Fixed in 11.1.6-h32Fixed in 11.1.4-h33Fixed in 10.2.18-h6Fixed in 10.2.16-h7Fixed in 10.2.13-h21Fixed in 10.2.10-h36Fixed in 10.2.7-h34 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.18-h6 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.15 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.12 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7 or later - Configuration
Disable User-ID™ Authentication Portal if it is not required.
Palo Alto Networks PAN-OS (User-ID™ Authentication Portal / Captive Portal) User-ID™ Authentication Portal = disabled if not required - Configuration
Disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress; keep Response Pages enabled only on interfaces in trust/internal zones where legitimate users' browsers ingress.
Palo Alto Networks PAN-OS (Interface Management Profile) Response Pages = disable - Compensating control
If Threat Prevention subscription is present, enable Threat ID 510019 from Applications and Threats content version 9097-10022 to block attacks for this vulnerability (decoder capabilities require PAN-OS 11.1 or later for Threat ID support).
- Compensating control
Restrict User-ID™ Authentication Portal access to only trusted zones (and/or trusted internal IP addresses) as a workaround until an official fix is released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0300?
CVE-2026-0300 is classified as a CRITICAL severity vulnerability.
How do I fix CVE-2026-0300?
To remediate CVE-2026-0300, upgrade to a patched version of PAN-OS, specifically 12.1.7, 12.1.4-h5, 11.2.12, or any other specified versions.
What type of vulnerability is CVE-2026-0300?
CVE-2026-0300 is a buffer overflow vulnerability affecting the User-ID™ Authentication Portal of PAN-OS.
Who is affected by CVE-2026-0300?
CVE-2026-0300 affects users of Palo Alto Networks PAN-OS software across various deployments, including PA-Series, VM-Series, and Cloud NGFW.
Can CVE-2026-0300 be exploited remotely?
Yes, CVE-2026-0300 allows unauthenticated attackers to exploit the vulnerability remotely.