Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC-CVE-2026-0300-exploit β€” Palo Alto - CVE-2026-0300 exploit | Kitploit
Tools/GitHubGitHub/sam00/poc-cve-2026-0300-exploit
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationNetwork SecurityPenetration TestingShellcode GenerationPayload DevelopmentBinary Exploitation
GitHubsam00/poc-cve-2026-0300-exploit

POC-CVE-2026-0300-exploit

301 month agoNot yet reviewed

Palo Alto - CVE-2026-0300 exploit

View Repository

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2026-0300 β€” PAN-OS User-ID Authentication Portal Buffer Overflow Exploit

Critical (CVSS 9.3) β€” Unauthenticated Remote Code Execution in Palo Alto Networks PAN-OS Captive Portal

Table of Contents

  • Overview
  • Vulnerability Details
  • Affected Versions
  • Architecture Diagrams
  • Project Structure
  • Installation
  • Scanner Usage β€” Step by Step
  • Exploit Usage β€” Step by Step
  • Payload Design
  • Mitigation
  • Disclaimer

Overview

CVE-2026-0300 is a critical buffer overflow vulnerability in the User-ID Authentication Portal (also known as Captive Portal) service of Palo Alto Networks PAN-OS software. An unauthenticated attacker can exploit this vulnerability by sending specially crafted packets to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls.

This repository contains a proof-of-concept exploit toolkit including:

  • Payload generator with version-specific offsets and x86_64 reverse shell shellcode
  • Scanner to detect vulnerable Captive Portal targets
  • Exploit with three modes: detection, crash (DoS), and full RCE

Vulnerability Details

FieldValue
CVE IDCVE-2026-0300
SeverityCRITICAL
CVSS 4.09.3 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H)
CWECWE-787: Out-of-bounds Write
CAPECCAPEC-100: Overflow Buffers
ImpactUnauthenticated Remote Code Execution (root)
Exploitation StatusLimited exploitation observed in the wild

Description

A buffer overflow vulnerability in the User-ID Authentication Portal service of PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall by sending specially crafted packets. The Captive Portal HTTP service uses fixed-size stack buffers for parsing HTTP headers, which can be overflowed via oversized header values (Cookie, User-Agent, URI, or POST body).

Required Configuration for Exposure

Both conditions must be true for a target to be vulnerable:

  1. User-ID Authentication Portal enabled β€” Device > User Identification > Authentication Portal Settings > Enable Authentication Portal
  2. Interface management profile with response pages β€” attached to an L3 interface in a zone where untrusted/internet traffic can ingress

Advisory Reference

  • Official Advisory: https://security.paloaltonetworks.com/CVE-2026-0300
  • Best Practice Guidelines: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC

Affected Versions

PAN-OS BranchVulnerable VersionsFixed Version
10.210.2.7, 10.2.10, 10.2.13, 10.2.16, 10.2.1810.2.7-h34+
11.111.1.0–11.1.1411.1.15+
11.211.2.0–11.2.1111.2.12+
12.112.1.0–12.1.612.1.7+

Not impacted: Prisma Access, Cloud NGFW, Panorama appliances.


Architecture Diagrams

System Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    CVE-2026-0300 Exploit Toolkit                     β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚                                                                      β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚  scan.py   │────▢│  HTTP Fingerprintβ”‚     β”‚  payload_gen.py    β”‚  β”‚
β”‚  β”‚  Scanner   β”‚     β”‚  + Version Check β”‚     β”‚                    β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚         β”‚                                   β”‚  β”‚ Version      β”‚  β”‚  β”‚
β”‚         β”‚  Reports:                         β”‚  β”‚ Offsets      β”‚  β”‚  β”‚
β”‚         β”‚  β€’ Portal detected?               β”‚  β”‚ (10.2/11.1/  β”‚  β”‚  β”‚
β”‚         β”‚  β€’ PAN-OS version                 β”‚  β”‚  11.2/12.1)  β”‚  β”‚  β”‚
β”‚         β”‚  β€’ Vulnerable?                    β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚         β–Ό                                   β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”‚  β”‚ Shellcode    β”‚  β”‚  β”‚
β”‚  β”‚ exploit.py │────▢│  Raw Socket     β”‚     β”‚  β”‚ Generator    β”‚  β”‚  β”‚
β”‚  β”‚  Exploit   β”‚     β”‚  HTTP Delivery  β”‚     β”‚  β”‚ (x86_64 rev  β”‚  β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚  β”‚  shell)      β”‚  β”‚  β”‚
β”‚         β”‚                                   β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚         β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”         β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚         β”œβ”€β–Άβ”‚ MODE: detect         β”‚         β”‚  β”‚ ROP Chain    β”‚  β”‚  β”‚
β”‚         β”‚  β”‚ Safe, non-intrusive  β”‚         β”‚  β”‚ (jmp rsp)    β”‚  β”‚  β”‚
β”‚         β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜         β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚         β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”         β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚         β”œβ”€β–Άβ”‚ MODE: crash          β”‚         β”‚  β”‚ HTTP Request β”‚  β”‚  β”‚
β”‚         β”‚  β”‚ DoS validation       β”‚         β”‚  β”‚ Builder      β”‚  β”‚  β”‚
β”‚         β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜         β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚         β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”         β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β”‚         └─▢│ MODE: rce            β”‚                                   β”‚
β”‚            β”‚ Reverse shell        β”‚     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”‚
β”‚            β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚ ReverseShellListener β”‚     β”‚
β”‚                    β”‚                    β”‚ (callback receiver)  β”‚     β”‚
β”‚                    β–Ό                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚
β”‚            β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                                      β”‚
β”‚            β”‚  Target Firewall β”‚                                      β”‚
β”‚            β”‚  PAN-OS Captive  β”‚                                      β”‚
β”‚            β”‚  Portal Service  β”‚                                      β”‚
β”‚            β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                                      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Scanner Flow

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Start Scan β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜
       β”‚
       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     No     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Target reachable?│──────────▢│  Skip port  β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜            β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
       β”‚ Yes
       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Send HTTP GET    β”‚
β”‚ to common ports  β”‚
β”‚ (443,80,8080,    β”‚
β”‚  8443,8843)      β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
       β”‚
       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     No     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Captive Portal   │──────────▢│ Not exposed β”‚
β”‚ fingerprint?     β”‚            β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ (login.esp,      β”‚
β”‚  User-ID, PA-,   β”‚
β”‚  PAN-OS, etc.)   β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
       β”‚ Yes
       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Extract PAN-OS   β”‚
β”‚ version from     β”‚
β”‚ Server header /  β”‚
β”‚ response body    β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
       β”‚
       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     No     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Version in       │──────────▢│ Not         β”‚
β”‚ vulnerable       β”‚            β”‚ vulnerable  β”‚
β”‚ range?           β”‚            β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
       β”‚ Yes
       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Report:          β”‚
β”‚ β€’ VULNERABLE     β”‚
β”‚ β€’ Version        β”‚
β”‚ β€’ Matched ranges β”‚
β”‚ β€’ SSL cert info  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Exploit Flow (RCE Mode)

Download Tool