← Back

CVE-2026-0300

nvd nist
Published: May 6, 2026Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:RedShow less
Source: psirt@paloaltonetworks.com (Secondary)

Description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

Affected (163)

Pan Os
1 product
Ruggedcom Ape1808 Firmware
Configuration A
162 vulnerable · 47 platform
Vulnerable SoftwareAffected Versions
Paloaltonetworks
Version 10.2.0
Version 10.2.10
Version 10.2.10 h10
Version 10.2.10 h12
Version 10.2.10 h14
Version 10.2.10 h17
Version 10.2.10 h18
Version 10.2.10 h21
Version 10.2.10 h27
Version 10.2.10 h2
Version 10.2.10 h30
Version 10.2.10 h31
Version 10.2.10 h3
Version 10.2.10 h4
Version 10.2.10 h5
Version 10.2.10 h7
Version 10.2.10 h9
Version 10.2.11
Version 10.2.12
Version 10.2.13
Version 10.2.13 h10
Version 10.2.13 h16
Version 10.2.13 h18
Version 10.2.13 h1
Version 10.2.13 h2
Version 10.2.13 h3
Version 10.2.13 h4
Version 10.2.13 h5
Version 10.2.13 h7
Version 10.2.14
Version 10.2.15
Version 10.2.16
Version 10.2.16 h1
Version 10.2.16 h4
Version 10.2.16 h6
Version 10.2.17
Version 10.2.18
Version 10.2.18 h1
Version 10.2.18 h5
Version 10.2.1
Version 10.2.2
Version 10.2.3
Version 10.2.4
Version 10.2.5
Version 10.2.6
Version 10.2.7
Version 10.2.7 h12
Version 10.2.7 h16
Version 10.2.7 h19
Version 10.2.7 h1
Version 10.2.7 h21
Version 10.2.7 h24
Version 10.2.7 h32
Version 10.2.7 h3
Version 10.2.7 h6
Version 10.2.7 h8
Version 10.2.8
Version 10.2.9
Version 11.1.0
Version 11.1.10
Version 11.1.10 h10
Version 11.1.10 h12
Version 11.1.10 h1
Version 11.1.10 h21
Version 11.1.10 h4
Version 11.1.10 h5
Version 11.1.10 h7
Version 11.1.10 h9
Version 11.1.11
Version 11.1.12
Version 11.1.13
Version 11.1.13 h1
Version 11.1.13 h2
Version 11.1.13 h3
Version 11.1.14
Version 11.1.1
Version 11.1.2
Version 11.1.3
Version 11.1.4
Version 11.1.4 h13
Version 11.1.4 h15
Version 11.1.4 h16
Version 11.1.4 h17
Version 11.1.4 h18
Version 11.1.4 h1
Version 11.1.4 h25
Version 11.1.4 h27
Version 11.1.4 h32
Version 11.1.4 h4
Version 11.1.4 h7
Version 11.1.4 h9
Version 11.1.5
Version 11.1.6
Version 11.1.6 h10
Version 11.1.6 h14
Version 11.1.6 h17
Version 11.1.6 h19
Version 11.1.6 h1
Version 11.1.6 h20
Version 11.1.6 h21
Version 11.1.6 h22
Version 11.1.6 h23
Version 11.1.6 h25
Version 11.1.6 h29
Version 11.1.6 h2
Version 11.1.6 h3
Version 11.1.6 h4
Version 11.1.6 h5
Version 11.1.6 h6
Version 11.1.6 h7
Version 11.1.7
Version 11.1.7 h1
Version 11.1.7 h2
Version 11.1.7 h4
Version 11.1.8
Version 11.1.9
Version 11.2.0
Version 11.2.10
Version 11.2.10 h1
Version 11.2.10 h2
Version 11.2.10 h3
Version 11.2.10 h4
Version 11.2.10 h5
Version 11.2.11
Version 11.2.1
Version 11.2.2
Version 11.2.3
Version 11.2.4
Version 11.2.4 h10
Version 11.2.4 h11
Version 11.2.4 h12
Version 11.2.4 h14
Version 11.2.4 h15
Version 11.2.4 h1
Version 11.2.4 h2
Version 11.2.4 h4
Version 11.2.4 h5
Version 11.2.4 h6
Version 11.2.4 h7
Version 11.2.4 h8
Version 11.2.4 h9
Version 11.2.5
Version 11.2.6
Version 11.2.7
Version 11.2.7 h10
Version 11.2.7 h11
Version 11.2.7 h12
Version 11.2.7 h1
Version 11.2.7 h2
Version 11.2.7 h3
Version 11.2.7 h4
Version 11.2.7 h7
Version 11.2.7 h8
Version 11.2.8
Version 11.2.9
Version 12.1.2
Version 12.1.3
Version 12.1.4
Version 12.1.4 h2
Version 12.1.4 h3
Version 12.1.5
Version 12.1.6
Running on/withPlatform Versions
Paloaltonetworks
Pa 1410
All versions
Paloaltonetworks
Pa 1420
All versions
Paloaltonetworks
Pa 3410
All versions
Paloaltonetworks
Pa 3420
All versions
Paloaltonetworks
Pa 3430
All versions
Paloaltonetworks
Pa 3440
All versions
Paloaltonetworks
Pa 410
All versions
Paloaltonetworks
Pa 410r
All versions
Paloaltonetworks
Pa 410r 5g
All versions
Paloaltonetworks
Pa 415
All versions
Paloaltonetworks
Pa 415 5g
All versions
Paloaltonetworks
Pa 440
All versions
Paloaltonetworks
Pa 445
All versions
Paloaltonetworks
Pa 450
All versions
Paloaltonetworks
Pa 450r
All versions
Paloaltonetworks
Pa 450r 5g
All versions
Paloaltonetworks
Pa 455
All versions
Paloaltonetworks
Pa 455 5g
All versions
Paloaltonetworks
Pa 455r 5g
All versions
Paloaltonetworks
Pa 460
All versions
Paloaltonetworks
Pa 501
All versions
Paloaltonetworks
Pa 505
All versions
Paloaltonetworks
Pa 510
All versions
Paloaltonetworks
Pa 520
All versions
Paloaltonetworks
Pa 540
All versions
Paloaltonetworks
Pa 5410
All versions
Paloaltonetworks
Pa 5420
All versions
Paloaltonetworks
Pa 5430
All versions
Paloaltonetworks
Pa 5440
All versions
Paloaltonetworks
Pa 5445
All versions
Paloaltonetworks
Pa 545 Poe
All versions
Paloaltonetworks
Pa 5450
All versions
Paloaltonetworks
Pa 550
All versions
Paloaltonetworks
Pa 5540
All versions
Paloaltonetworks
Pa 555 Poe
All versions
Paloaltonetworks
Pa 5550
All versions
Paloaltonetworks
Pa 5560
All versions
Paloaltonetworks
Pa 5570
All versions
Paloaltonetworks
Pa 5580
All versions
Paloaltonetworks
Pa 560
All versions
Paloaltonetworks
Pa 7500
All versions
Paloaltonetworks
Pa 7500 Dpc A
All versions
Paloaltonetworks
Vm 100
All versions
Paloaltonetworks
Vm 300
All versions
Paloaltonetworks
Vm 50
All versions
Paloaltonetworks
Vm 500
All versions
Paloaltonetworks
Vm 700
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Ruggedcom Ape1808
All versions

References (3)

Source: psirt@paloaltonetworks.com
MitigationVendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.