Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-0300 — Non-destructive exposure survey tool for assessing PAN-OS User-ID Authentication Portal surfaces related to CVE-2026-0300, performing safe HTTP(S) checks and version-based risk assessment. | Kitploit
Tools/GitHubGitHub/shizuku198411/cve-2026-0300
Defensive ToolsReconnaissanceVulnerability ScannersInformation GatheringWeb SecurityNetwork Security
GitHubshizuku198411/cve-2026-0300

CVE-2026-0300

Non-destructive exposure survey tool for assessing PAN-OS User-ID Authentication Portal surfaces related to CVE-2026-0300, performing safe HTTP(S) checks and version-based risk assessment.

View Repository
1245 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PAN-OS CVE-2026-0300 Non-Destructive Exposure Survey Tool

Overview

This tool is a non-destructive exposure survey utility for assessing whether a target PAN-OS service may expose network-accessible surfaces related to CVE-2026-0300.

The tool is intended for authorized defensive security validation, asset exposure review, and vulnerability triage. It does not exploit the vulnerability, does not send memory-corruption payloads, and does not attempt to crash or compromise the target device.

Target CVE

This tool is designed for exposure assessment related to:

  • CVE: CVE-2026-0300
  • Vendor: Palo Alto Networks
  • Product: PAN-OS
  • Affected component: User-ID Authentication Portal, also known as Captive Portal
  • Vulnerability type: Buffer overflow / out-of-bounds write
  • Impact: Potential unauthenticated remote code execution with root privileges on affected devices
  • Severity: Critical
  • CVSS: 9.3
  • Exploit maturity: ATTACKED

According to Palo Alto Networks, CVE-2026-0300 affects PAN-OS deployments where the User-ID Authentication Portal is enabled and reachable from untrusted networks. PA-Series and VM-Series firewalls may be affected. Prisma Access, Cloud NGFW, and Panorama are listed as not affected in the official advisory.

What This Tool Checks

The tool performs safe network and HTTP(S)-level checks to identify whether a target appears to expose PAN-OS portal-related services.

It checks:

  • TCP reachability for the specified IP/port.
  • HTTPS reachability.
  • HTTP reachability when --scheme both or --scheme http is used.
  • Safe HTTP methods only:
    • HEAD
    • GET
    • OPTIONS
  • Portal-related paths, including:
    • /
    • /php/login.php
    • /php/uid.php
    • /php/uidlogin.php
    • /sslmgr
    • /global-protect/login.esp
  • HTTP response status codes.
  • Basic response fingerprints that may indicate:
    • PAN-OS
    • Palo Alto Networks
    • Captive Portal
    • User-ID Authentication Portal
    • GlobalProtect
    • Response pages
  • Optional self-reported PAN-OS version assessment using --pan-os-ver.

HTTPS certificate verification is disabled by default because PAN-OS administrative and portal services often use self-signed or privately issued certificates.

What This Tool Does Not Do

This tool does not:

  • Send exploit payloads.
  • Send memory-corruption buffers.
  • Attempt authentication bypass.
  • Attempt remote code execution.
  • Perform crash testing.
  • Confirm exploitability.
  • Modify the target device.
  • Authenticate to PAN-OS.
  • Read PAN-OS configuration directly.

The tool only provides an external network-observable exposure assessment and, if --pan-os-ver is provided, a self-reported version-based risk assessment.

What You Can Learn From the Results

The tool helps answer the following questions:

1. Is the target port reachable?

The tool checks whether the scanner host can establish a TCP connection to the specified target and port.

Example finding:

tcp=True
https=True

This means the target port is reachable from the scanner host and accepts HTTPS connections.

2. Does the service behave like an HTTP(S) service?

The tool sends safe HTTP(S) requests and records response status codes.

Example findings:

HTTPS HEAD /: HTTP/1.1 403 Forbidden
HTTPS GET /php/uid.php: HTTP/1.1 500 Internal Server Error

This means the service is reachable and is processing HTTP(S) requests.

3. Are portal-related paths externally reachable?

The tool checks paths commonly associated with PAN-OS portal or response-page functionality.

Examples:

/php/login.php
/php/uid.php
/php/uidlogin.php

Non-404 responses from these paths may indicate that portal-related handlers are reachable from the scanner host.

4. Does the target look like a PAN-OS/User-ID portal?

The tool looks for lightweight textual indicators in response headers, titles, redirects, cookies, and response body samples.

Examples of indicators:

palo alto
pan-os
globalprotect
captive portal
user-id
authentication portal
response page

These indicators increase confidence that the exposed service is related to PAN-OS portal functionality.

5. Is the supplied PAN-OS version affected?

If --pan-os-ver is provided, the tool compares the supplied version against the affected/fixed thresholds from the official advisory table embedded in the script.

Example:

--pan-os-ver 10.2.4-h2

Example result:

patch_status: AFFECTED_BY_VERSION
version_status: AFFECTED_VERSION
combined_risk=HIGH

If --pan-os-ver is not provided, the tool displays the affected/fixed version table and reports the version status as unknown.

Installation

This tool uses only Python standard library modules.

No external Python dependencies are required.

python3 --version

Recommended:

Python 3.8+

A minimal requirements.txt can be used:

# No external dependencies required.
# This tool uses only Python standard library modules.

Basic Usage

Scan a single target and port

python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.254 \
  -p 6082

Scan with a self-reported PAN-OS version

python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.254 \
  -p 6082 \
  --pan-os-ver 10.2.4-h2

Show detailed per-request observations

python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.254 \
  -p 6082 \
  --pan-os-ver 10.2.4-h2 \
  --verbose

Probe both HTTPS and HTTP

python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.254 \
  -p 6082 \
  --scheme both

Use minimal path probing

By default, the tool probes all safe known paths.

Use --minimal to check only:

  • /
  • /php/login.php
python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.254 \
  -p 6082 \
  --minimal

Scan multiple ports

python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.254 \
  -p 443,6082,6081-6083 \
  --scheme both

Scan a CIDR range

python3 panos_cve_2026_0300_diag.py \
  -t 172.16.20.0/24 \
  -p 6082 \
  --csv-out results.csv \
  --json-out results.json

Scan targets from a file

Create targets.txt:

172.16.20.254
172.16.20.253
172.16.21.0/24

Run:

python3 panos_cve_2026_0300_diag.py \
  -T targets.txt \
  -p 6082 \
  --json-out results.json

Command-Line Options

OptionDescription
-t, --targetTarget IP, hostname, or CIDR. Comma-separated values are supported.
-T, --targets-fileFile containing targets, one per line. CIDR entries are supported.
-p, --portsPort or port range. Example: 6082, 443,6082, 6081-6083.
--schemeProbe scheme: https, http, or both. Default: https.
--pan-os-verSelf-reported PAN-OS version, such as 10.2.4-h2.
--timeoutSocket timeout in seconds. Default: 4.0.
--max-bytesMaximum response bytes to read per request. Default: 16384.
--minimalProbe only / and /php/login.php.
--verbosePrint all request observations.
--quietReduce console output.
--json-outWrite full results to a JSON file.
--csv-outWrite summary results to a CSV file.

Result Interpretation

The tool produces three main types of assessment:

  1. Exposure level
  2. Version/patch status
  3. Combined risk

Exposure Level Reference

Download Tool