CVE-2026-0300

EUVD-2026-27879
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. 

The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.

Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
paloaltonetworkspan-os
10.2.0
paloaltonetworkspan-os
10.2.1
paloaltonetworkspan-os
10.2.2
paloaltonetworkspan-os
10.2.3
paloaltonetworkspan-os
10.2.4
paloaltonetworkspan-os
10.2.5
paloaltonetworkspan-os
10.2.6
paloaltonetworkspan-os
10.2.7
paloaltonetworkspan-os
10.2.7:h1
paloaltonetworkspan-os
10.2.7:h12
paloaltonetworkspan-os
10.2.7:h16
paloaltonetworkspan-os
10.2.7:h19
paloaltonetworkspan-os
10.2.7:h21
paloaltonetworkspan-os
10.2.7:h24
paloaltonetworkspan-os
10.2.7:h3
paloaltonetworkspan-os
10.2.7:h32
paloaltonetworkspan-os
10.2.7:h6
paloaltonetworkspan-os
10.2.7:h8
paloaltonetworkspan-os
10.2.8
paloaltonetworkspan-os
10.2.9
paloaltonetworkspan-os
10.2.10
paloaltonetworkspan-os
10.2.10:h10
paloaltonetworkspan-os
10.2.10:h12
paloaltonetworkspan-os
10.2.10:h14
paloaltonetworkspan-os
10.2.10:h17
paloaltonetworkspan-os
10.2.10:h18
paloaltonetworkspan-os
10.2.10:h2
paloaltonetworkspan-os
10.2.10:h21
paloaltonetworkspan-os
10.2.10:h27
paloaltonetworkspan-os
10.2.10:h3
paloaltonetworkspan-os
10.2.10:h30
paloaltonetworkspan-os
10.2.10:h31
paloaltonetworkspan-os
10.2.10:h4
paloaltonetworkspan-os
10.2.10:h5
paloaltonetworkspan-os
10.2.10:h7
paloaltonetworkspan-os
10.2.10:h9
paloaltonetworkspan-os
10.2.11
paloaltonetworkspan-os
10.2.12
paloaltonetworkspan-os
10.2.13
paloaltonetworkspan-os
10.2.13:h1
paloaltonetworkspan-os
10.2.13:h10
paloaltonetworkspan-os
10.2.13:h16
paloaltonetworkspan-os
10.2.13:h18
paloaltonetworkspan-os
10.2.13:h2
paloaltonetworkspan-os
10.2.13:h3
paloaltonetworkspan-os
10.2.13:h4
paloaltonetworkspan-os
10.2.13:h5
paloaltonetworkspan-os
10.2.13:h7
paloaltonetworkspan-os
10.2.14
paloaltonetworkspan-os
10.2.15
paloaltonetworkspan-os
10.2.16
paloaltonetworkspan-os
10.2.16:h1
paloaltonetworkspan-os
10.2.16:h4
paloaltonetworkspan-os
10.2.16:h6
paloaltonetworkspan-os
10.2.17
paloaltonetworkspan-os
10.2.18
paloaltonetworkspan-os
10.2.18:h1
paloaltonetworkspan-os
10.2.18:h5
paloaltonetworkspan-os
11.1.0
paloaltonetworkspan-os
11.1.1
paloaltonetworkspan-os
11.1.2
paloaltonetworkspan-os
11.1.3
paloaltonetworkspan-os
11.1.4
paloaltonetworkspan-os
11.1.4:h1
paloaltonetworkspan-os
11.1.4:h13
paloaltonetworkspan-os
11.1.4:h15
paloaltonetworkspan-os
11.1.4:h16
paloaltonetworkspan-os
11.1.4:h17
paloaltonetworkspan-os
11.1.4:h18
paloaltonetworkspan-os
11.1.4:h25
paloaltonetworkspan-os
11.1.4:h27
paloaltonetworkspan-os
11.1.4:h32
paloaltonetworkspan-os
11.1.4:h4
paloaltonetworkspan-os
11.1.4:h7
paloaltonetworkspan-os
11.1.4:h9
paloaltonetworkspan-os
11.1.5
paloaltonetworkspan-os
11.1.6
paloaltonetworkspan-os
11.1.6:h1
paloaltonetworkspan-os
11.1.6:h10
paloaltonetworkspan-os
11.1.6:h14
paloaltonetworkspan-os
11.1.6:h17
paloaltonetworkspan-os
11.1.6:h19
paloaltonetworkspan-os
11.1.6:h2
paloaltonetworkspan-os
11.1.6:h20
paloaltonetworkspan-os
11.1.6:h21
paloaltonetworkspan-os
11.1.6:h22
paloaltonetworkspan-os
11.1.6:h23
paloaltonetworkspan-os
11.1.6:h25
paloaltonetworkspan-os
11.1.6:h29
paloaltonetworkspan-os
11.1.6:h3
paloaltonetworkspan-os
11.1.6:h4
paloaltonetworkspan-os
11.1.6:h5
paloaltonetworkspan-os
11.1.6:h6
paloaltonetworkspan-os
11.1.6:h7
paloaltonetworkspan-os
11.1.7
paloaltonetworkspan-os
11.1.7:h1
paloaltonetworkspan-os
11.1.7:h2
paloaltonetworkspan-os
11.1.7:h4
paloaltonetworkspan-os
11.1.8
paloaltonetworkspan-os
11.1.9
paloaltonetworkspan-os
11.1.10
paloaltonetworkspan-os
11.1.10:h1
paloaltonetworkspan-os
11.1.10:h10
paloaltonetworkspan-os
11.1.10:h12
paloaltonetworkspan-os
11.1.10:h21
paloaltonetworkspan-os
11.1.10:h4
paloaltonetworkspan-os
11.1.10:h5
paloaltonetworkspan-os
11.1.10:h7
paloaltonetworkspan-os
11.1.10:h9
paloaltonetworkspan-os
11.1.11
paloaltonetworkspan-os
11.1.12
paloaltonetworkspan-os
11.1.13
paloaltonetworkspan-os
11.1.13:h1
paloaltonetworkspan-os
11.1.13:h2
paloaltonetworkspan-os
11.1.13:h3
paloaltonetworkspan-os
11.1.14
paloaltonetworkspan-os
11.2.0
paloaltonetworkspan-os
11.2.1
paloaltonetworkspan-os
11.2.2
paloaltonetworkspan-os
11.2.3
paloaltonetworkspan-os
11.2.4
paloaltonetworkspan-os
11.2.4:h1
paloaltonetworkspan-os
11.2.4:h10
paloaltonetworkspan-os
11.2.4:h11
paloaltonetworkspan-os
11.2.4:h12
paloaltonetworkspan-os
11.2.4:h14
paloaltonetworkspan-os
11.2.4:h15
paloaltonetworkspan-os
11.2.4:h2
paloaltonetworkspan-os
11.2.4:h4
paloaltonetworkspan-os
11.2.4:h5
paloaltonetworkspan-os
11.2.4:h6
paloaltonetworkspan-os
11.2.4:h7
paloaltonetworkspan-os
11.2.4:h8
paloaltonetworkspan-os
11.2.4:h9
paloaltonetworkspan-os
11.2.5
paloaltonetworkspan-os
11.2.6
paloaltonetworkspan-os
11.2.7
paloaltonetworkspan-os
11.2.7:h1
paloaltonetworkspan-os
11.2.7:h10
paloaltonetworkspan-os
11.2.7:h11
paloaltonetworkspan-os
11.2.7:h12
paloaltonetworkspan-os
11.2.7:h2
paloaltonetworkspan-os
11.2.7:h3
paloaltonetworkspan-os
11.2.7:h4
paloaltonetworkspan-os
11.2.7:h7
paloaltonetworkspan-os
11.2.7:h8
paloaltonetworkspan-os
11.2.8
paloaltonetworkspan-os
11.2.9
paloaltonetworkspan-os
11.2.10
paloaltonetworkspan-os
11.2.10:h1
paloaltonetworkspan-os
11.2.10:h2
paloaltonetworkspan-os
11.2.10:h3
paloaltonetworkspan-os
11.2.10:h4
paloaltonetworkspan-os
11.2.10:h5
paloaltonetworkspan-os
11.2.11
paloaltonetworkspan-os
12.1.2
paloaltonetworkspan-os
12.1.3
paloaltonetworkspan-os
12.1.4
paloaltonetworkspan-os
12.1.4:h2
paloaltonetworkspan-os
12.1.4:h3
paloaltonetworkspan-os
12.1.5
paloaltonetworkspan-os
12.1.6
𝑥
= Vulnerable software versions
Vulnerability Media Exposure