CVE-2026-0257

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security r…

Severity
medium
Aktiv ausgenutzt
aktiv ausgenutzt (KEV)
99.7 %
Kritisch — Modell sagt sehr hohe Ausnutzungs-Wahrscheinlichkeit in den nächsten 30 Tagen.
Veröffentlicht
2026-05-13 18:15 UTC
CWE-565

Weakness-Klassen (CWE)

  • CWE-565Base

    Reliance on Cookies without Validation and Integrity Checking

    The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

    cwe.mitre.org →

Beschreibung

Authentifizierungs-Umgehungs-Schwachstellen im GlobalProtect-Portal und -Gateway der Palo Alto Networks PAN-OS®-Software ermöglichen es dem Angreifer, Sicherheitseinschränkungen zu umgehen und eine nicht autorisierte VPN-Verbindung herzustellen. Panorama und Cloud NGFW sind von diesen Problemen nicht betroffen.

Quelle: EUVD

Betroffene Betriebssysteme

  • other

    palo_alto_networks / pan-os10.2.0

  • other

    palo_alto_networks / pan-os10.2.1

  • other

    palo_alto_networks / pan-os10.2.10

  • other

    palo_alto_networks / pan-os10.2.11

  • other

    palo_alto_networks / pan-os10.2.12

  • other

    palo_alto_networks / pan-os10.2.13

  • other

    palo_alto_networks / pan-os10.2.14

  • other

    palo_alto_networks / pan-os10.2.15

  • other

    palo_alto_networks / pan-os10.2.16

  • other

    palo_alto_networks / pan-os10.2.17

  • other

    palo_alto_networks / pan-os10.2.18

  • other

    palo_alto_networks / pan-os10.2.2

  • other

    palo_alto_networks / pan-os10.2.3

  • other

    palo_alto_networks / pan-os10.2.4

  • other

    palo_alto_networks / pan-os10.2.5

  • other

    palo_alto_networks / pan-os10.2.6

  • other

    palo_alto_networks / pan-os10.2.7

  • other

    palo_alto_networks / pan-os10.2.8

  • other

    palo_alto_networks / pan-os10.2.9

  • other

    palo_alto_networks / pan-os11.1.0

  • other

    palo_alto_networks / pan-os11.1.1

  • other

    palo_alto_networks / pan-os11.1.10

  • other

    palo_alto_networks / pan-os11.1.11

  • other

    palo_alto_networks / pan-os11.1.12

Öffentliche Exploit-Referenzen

Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.

Quellen & Referenzen