CVE-2026-0257
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security r…
Weakness classes (CWE)
CWE-565Base
Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
cwe.mitre.org →
Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
Source: EUVD
Affected operating systems
other
palo_alto_networks / pan-os10.2.0
other
palo_alto_networks / pan-os10.2.1
other
palo_alto_networks / pan-os10.2.10
other
palo_alto_networks / pan-os10.2.11
other
palo_alto_networks / pan-os10.2.12
other
palo_alto_networks / pan-os10.2.13
other
palo_alto_networks / pan-os10.2.14
other
palo_alto_networks / pan-os10.2.15
other
palo_alto_networks / pan-os10.2.16
other
palo_alto_networks / pan-os10.2.17
other
palo_alto_networks / pan-os10.2.18
other
palo_alto_networks / pan-os10.2.2
other
palo_alto_networks / pan-os10.2.3
other
palo_alto_networks / pan-os10.2.4
other
palo_alto_networks / pan-os10.2.5
other
palo_alto_networks / pan-os10.2.6
other
palo_alto_networks / pan-os10.2.7
other
palo_alto_networks / pan-os10.2.8
other
palo_alto_networks / pan-os10.2.9
other
palo_alto_networks / pan-os11.1.0
other
palo_alto_networks / pan-os11.1.1
other
palo_alto_networks / pan-os11.1.10
other
palo_alto_networks / pan-os11.1.11
other
palo_alto_networks / pan-os11.1.12
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.