CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute…
How it works
The weakness is classified as CWE-787, an out-of-bounds write. The flaw exists in the User-ID Authentication Portal, also known as the Captive Portal service.
An attacker abuses the issue by sending specially crafted packets to the service. This can result in arbitrary code execution with root privileges on the firewall.
Am I affected? How to find it in your systems
The vulnerability affects Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls where the User-ID Authentication Portal service is present.
- Inventory all PAN-OS firewalls in your environment and note whether the User-ID Authentication Portal is enabled.
- Check configurations that expose the portal to untrusted networks or zones.
- Confirm exact affected versions and build details against the vendor advisory, as public detail is limited here.
- Review firewall logs and telemetry for unexpected traffic or authentication attempts directed at the portal service.
How to remediate
Apply the vendor patches released by Palo Alto Networks. Follow the designated patch instructions for your specific PAN-OS deployments.
- Apply mitigations per the vendor advisory.
- Follow applicable BOD 22-01 guidance for any cloud services involved.
If you can't patch immediately
Until a patch can be applied, implement the documented workarounds.
- Restrict User-ID Authentication Portal access to only trusted zones.
- Disable the User-ID Authentication Portal if it is not required in your environment.
- Consider discontinuing use of the product if the above mitigations cannot be applied.
If your data may have been exposed
Actively exploited vulnerabilities of this type can lead to breaches that expose credentials or network access. You can run a free exposure scan of your email addresses to check against known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.