A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0300 | Mitigation Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-967325.html | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300 | US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-06 19:16
Updated : 2026-06-17 10:10
NVD link : CVE-2026-0300
Mitre link : CVE-2026-0300
CVE.ORG link : CVE-2026-0300
JSON object : View
Products Affected
paloaltonetworks
- pa-455-5g
- pa-455r-5g
- pa-450r
- pa-545-poe
- pa-550
- vm-700
- pa-540
- pa-3440
- pa-7500-dpc-a
- pa-510
- pa-410r-5g
- pa-450r-5g
- pa-560
- pa-5550
- pa-5450
- vm-500
- pa-415
- pa-410
- pa-410r
- pa-7500
- pa-455
- vm-300
- vm-100
- pa-505
- pa-3410
- pa-440
- pa-5540
- pa-450
- pa-460
- pa-5440
- pa-3420
- pa-1410
- pa-5410
- pan-os
- pa-1420
- pa-3430
- pa-520
- pa-5580
- pa-415-5g
- pa-555-poe
- vm-50
- pa-5570
- pa-5430
- pa-5445
- pa-501
- pa-445
- pa-5420
- pa-5560
siemens
- ruggedcom_ape1808_firmware
- ruggedcom_ape1808
CWE
CWE-787
Out-of-bounds Write
