PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Summary
| CVE | CVE-2026-0257 |
|---|---|
| State | PUBLISHED |
| Assigner | palo_alto |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-13 19:17:01 UTC |
| Updated | 2026-06-01 12:33:52 UTC |
| Description | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. |
Risk And Classification
Primary CVSS: v4.0 7.8 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
EPSS: 0.363440000 probability, percentile 0.971970000 (date 2026-06-02)
CISA KEV: Listed on 2026-05-29; due 2026-06-01; ransomware use Unknown
Problem Types: CWE-565 | CWE-565 CWE-565 Reliance on Cookies without Validation and Integrity Checking
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.8 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/C... |
| 4.0 | CNA | CVSS | 7.8 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/A... |
| 3.1 | [email protected] | Primary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA Known Exploited Vulnerability
| Vendor | Palo Alto Networks |
|---|---|
| Product | PAN-OS |
| Name | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Paloaltonetworks | Pan-os | All | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | All | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h14 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h17 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h18 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h21 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h27 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h30 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h31 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.11 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.12 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h16 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h18 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.13 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.14 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.15 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.16 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.16 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.16 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.16 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.17 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.18 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.18 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.18 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h16 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h18 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h19 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h21 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h24 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h32 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h8 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.8 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.9 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.0 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.1 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h21 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.10 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.11 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.12 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.13 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.13 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.13 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.13 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.14 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h13 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h15 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h16 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h17 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h18 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h25 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h27 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h32 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.5 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h14 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h17 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h19 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h20 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h21 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h22 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h23 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h25 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h29 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.6 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.7 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.7 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.7 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.7 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.8 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.9 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.0 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.1 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.10 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.11 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.2 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.3 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h11 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h14 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h15 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h8 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.5 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.6 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h11 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h13 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.7 | h8 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.8 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.9 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.2 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.3 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.4 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.4 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.4 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.4 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.5 | All | All | All |
| Operating System | Paloaltonetworks | Pan-os | 12.1.6 | All | All | All |
| Application | Paloaltonetworks | Prisma Access | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Palo Alto Networks | Cloud NGFW | unaffected All custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 12.1.0 12.1.7, 12.1.4-h6 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 11.2.0 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 11.1.0 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 10.2.0 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34 custom | Not specified |
| CNA | Palo Alto Networks | Prisma Access | affected 10.2.0 10.2.10-h36 custom | Not specified |
| CNA | Palo Alto Networks | Prisma Access | affected 11.2.0 11.2.7-h13 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.paloaltonetworks.com/CVE-2026-0257 | [email protected] | security.paloaltonetworks.com | Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
CNA: Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-05-13T16:00:00.000Z | Initial publication. |
| CNA | 2026-05-29T17:15:00.000Z | Updated exploitation status. |
| ADP | 2026-05-29T00:00:00.000Z | CVE-2026-0257 added to CISA KEV |
Solutions
CNA: Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.6 Upgrade to 12.1.7 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h6 or 12.1.7 or later. PAN-OS 11.2 11.2.11 or later Upgrade to 11.2.12 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h7 or 11.2.12 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h14 or 11.2.12 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h17 or 11.2.12 or later. PAN-OS 11.1 11.1.14 or later Upgrade to 11.1.15 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h5 or 11.1.15 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h25 or 11.1.15 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h6 or 11.1.15 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h32 or 11.1.15 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h33 or 11.1.15 or later. PAN-OS 10.2 10.2.17 through 10.2.18-h* Upgrade to 10.2.18 or 10.2.18-h6 or later. 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h7 or 10.2.18 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h21 or 10.2.18 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h36 or 10.2.18 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h34 or 10.2.18 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version. Prisma Access 10.2 10.2.0 through 10.2.10-h* Upgrade to 10.2.10-h36 or later. Prisma Access 11.2 11.2.0 through 11.2.7-h* Upgrade to 11.2.7-h13 or later.
CNA: Note: With this fix, if the firewall is configured to use an authentication override cookie for the GlobalProtect Portal or Gateway, it will regenerate the cookie using a more secure method. Therefore, GP users will need to re-authenticate after a PAN-OS upgrade, even if a valid cookie is present. This is a one time requirement. Once they re-authenticate after the upgrade, the authentication override cookie and its validity will work as they do today.
Workarounds
CNA: Customers can mitigate the risk of this issue by taking any of the following actions: * Use a dedicated certificate for Authentication Override cookies: Generate a new certificate exclusively for authentication override cookies and store it securely. Do not reuse the portal or gateway certificate, and do not share this certificate with other features or users. * Disable Authentication Override: Uncheck the Authentication Override options (for generating and accepting cookies) in the GlobalProtect portal and gateway configuration.
Exploits
CNA: Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.