CVE-2026-0257
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security r…
Weakness-Klassen (CWE)
CWE-565Base
Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
cwe.mitre.org →
Beschreibung
Authentifizierungs-Umgehungs-Schwachstellen im GlobalProtect-Portal und -Gateway der Palo Alto Networks PAN-OS®-Software ermöglichen es dem Angreifer, Sicherheitseinschränkungen zu umgehen und eine nicht autorisierte VPN-Verbindung herzustellen. Panorama und Cloud NGFW sind von diesen Problemen nicht betroffen.
Quelle: EUVD
Betroffene Betriebssysteme
other
palo_alto_networks / pan-os10.2.0
other
palo_alto_networks / pan-os10.2.1
other
palo_alto_networks / pan-os10.2.10
other
palo_alto_networks / pan-os10.2.11
other
palo_alto_networks / pan-os10.2.12
other
palo_alto_networks / pan-os10.2.13
other
palo_alto_networks / pan-os10.2.14
other
palo_alto_networks / pan-os10.2.15
other
palo_alto_networks / pan-os10.2.16
other
palo_alto_networks / pan-os10.2.17
other
palo_alto_networks / pan-os10.2.18
other
palo_alto_networks / pan-os10.2.2
other
palo_alto_networks / pan-os10.2.3
other
palo_alto_networks / pan-os10.2.4
other
palo_alto_networks / pan-os10.2.5
other
palo_alto_networks / pan-os10.2.6
other
palo_alto_networks / pan-os10.2.7
other
palo_alto_networks / pan-os10.2.8
other
palo_alto_networks / pan-os10.2.9
other
palo_alto_networks / pan-os11.1.0
other
palo_alto_networks / pan-os11.1.1
other
palo_alto_networks / pan-os11.1.10
other
palo_alto_networks / pan-os11.1.11
other
palo_alto_networks / pan-os11.1.12
Öffentliche Exploit-Referenzen
Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.