A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
An attacker sends specially crafted network packets to the User-ID Authentication Portal (Captive Portal) service running in PAN-OS. Due to a CWE-787 error (out-of-bounds write), a buffer overflow occurs in the memory of the portal-handling process. This allows the attacker to take control of the program's execution flow and execute arbitrary code with root privileges without prior authentication. The risk is significantly reduced if access to the Captive Portal is restricted exclusively to trusted internal IP addresses in accordance with the vendor's guidelines.
An attacker gains full control of the device with root privileges, enabling arbitrary system command execution, backdoor installation, theft of configuration and credentials, and use of the device as an entry point to the internal network.
Apply patches available from the vendor according to the references (https://security.paloaltonetworks.com/CVE-2026-0300). Until the patch is implemented, as a workaround, immediately restrict access to the User-ID Authentication Portal (Captive Portal) service exclusively to trusted internal IP addresses in accordance with the vendor's guidelines.
Palo Alto Networks PA series firewalls (PA-440, PA-1410, PA-5560, PA-5580, PA-7500) and VM-Series running PAN-OS software with the User-ID Authentication Portal (Captive Portal) service enabled. Prisma Access, Cloud NGFW, and Panorama devices are not vulnerable.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:RedPalo Alto Networks Pa 1410
HWPaloaltonetworksall versionsPalo Alto Networks Pa 1420
HWPaloaltonetworksall versionsPalo Alto Networks Pa 3410
HWPaloaltonetworksall versionsPalo Alto Networks Pa 3420
HWPaloaltonetworksall versionsPalo Alto Networks Pa 3430
HWPaloaltonetworksall versionsPalo Alto Networks Pa 3440
HWPaloaltonetworksall versionsPalo Alto Networks Pa 410
HWPaloaltonetworksall versionsPalo Alto Networks Pa 410r
HWPaloaltonetworksall versionsPalo Alto Networks Pa 410r 5g
HWPaloaltonetworksall versionsPalo Alto Networks Pa 415
HWPaloaltonetworksall versionsPalo Alto Networks Pa 415 5g
HWPaloaltonetworksall versionsPalo Alto Networks Pa 440
HWPaloaltonetworksall versionsPalo Alto Networks Pa 445
HWPaloaltonetworksall versionsPalo Alto Networks Pa 450
HWPaloaltonetworksall versionsPalo Alto Networks Pa 450r
HWPaloaltonetworksall versionsPalo Alto Networks Pa 450r 5g
HWPaloaltonetworksall versionsPalo Alto Networks Pa 455
HWPaloaltonetworksall versionsPalo Alto Networks Pa 455 5g
HWPaloaltonetworksall versionsPalo Alto Networks Pa 455r 5g
HWPaloaltonetworksall versionsPalo Alto Networks Pa 460
HWPaloaltonetworksall versionsPalo Alto Networks Pa 501
HWPaloaltonetworksall versionsPalo Alto Networks Pa 505
HWPaloaltonetworksall versionsPalo Alto Networks Pa 510
HWPaloaltonetworksall versionsPalo Alto Networks Pa 520
HWPaloaltonetworksall versionsPalo Alto Networks Pa 540
HWPaloaltonetworksall versionsPalo Alto Networks Pa 5410
HWPaloaltonetworksall versionsPalo Alto Networks Pa 5420
HWPaloaltonetworksall versionsPalo Alto Networks Pa 5430
HWPaloaltonetworksall versionsPalo Alto Networks Pa 5440
HWPaloaltonetworksall versionsPalo Alto Networks Pa 5445
HWPaloaltonetworksall versions
CISA KEV — detailsi
- Vendori
- Palo Alto Networks ↗
- Producti
- PAN-OS
- Added to KEVi
- May 6, 2026
- Remediation deadline (US Federal)i
- May 9, 2026(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
Related vulnerabilities
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
Authentication bypass w PAN-OS umożliwiający przejęcie uprawnień administratora
RCE jako root w GlobalProtect — command injection w PAN-OS
PAN-OS: Pomijanie uwierzytelnienia SAML przez brak weryfikacji podpisów