VDB

CVE-2026-0300

CVE-2026-0300 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

A critical security vulnerability, CVE-2026-0300, has been identified in Palo Alto Networks PAN-OS and affects the User-ID Authentication Portal service on PA-Series and VM-Series firewalls. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability. This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal. This feature is not enabled by default. Customers are impacted if both of the following conditions are true: User-ID Authentication Portal configured in the User-ID Authentication Portal Settings page. An interface management profile with response page enabled and attached to any L3 interface in any zone where untrusted/internet traffic can ingress. The risk of this issue is greatly reduced if you secure access to the User-ID Authentication Portal per the best practice guidelines by restricting access to only trusted internal IP addresses. Successful exploitation results in root access on the underlying OS of the firewall. Root access means the attacker has unrestricted privileges on the firewall. They can modify system files, install malware, or change firewall configurations. Limited exploitation has been observed targeting Palo Alto Networks User-ID Authentication Portals that are exposed to untrusted IP addresses and/or the public internet. Post-exploitation activity includes deployment of publicly available tunneling tools (EarthWorm, ReverseSocks5), Active Directory enumeration using credentials likely obtained from the firewall, and the systematic destruction of logs and other evidence of compromise.

EPSS 4.54% · 89.4th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
4.54%
89.4th percentile

Affected Products

VendorProductVersions
Palo Alto NetworksPalo Alto PAN-OS User-ID Authentication Portal

Timeline

  • May 5, 2026 CVE Published
  • May 5, 2026 PoC Published
  • May 5, 2026 PoC Published
  • May 6, 2026 CISA KEV Added
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
  • May 6, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›