
Non-destructive exposure survey tool for assessing PAN-OS User-ID Authentication Portal surfaces related to CVE-2026-0300, performing safe HTTP(S) checks and version-based risk assessment.
This tool is a non-destructive exposure survey utility for assessing whether a target PAN-OS service may expose network-accessible surfaces related to CVE-2026-0300.
The tool is intended for authorized defensive security validation, asset exposure review, and vulnerability triage. It does not exploit the vulnerability, does not send memory-corruption payloads, and does not attempt to crash or compromise the target device.
This tool is designed for exposure assessment related to:
According to Palo Alto Networks, CVE-2026-0300 affects PAN-OS deployments where the User-ID Authentication Portal is enabled and reachable from untrusted networks. PA-Series and VM-Series firewalls may be affected. Prisma Access, Cloud NGFW, and Panorama are listed as not affected in the official advisory.
The tool performs safe network and HTTP(S)-level checks to identify whether a target appears to expose PAN-OS portal-related services.
It checks:
--scheme both or --scheme http is used.HEADGETOPTIONS//php/login.php/php/uid.php/php/uidlogin.php/sslmgr/global-protect/login.esp--pan-os-ver.HTTPS certificate verification is disabled by default because PAN-OS administrative and portal services often use self-signed or privately issued certificates.
This tool does not:
The tool only provides an external network-observable exposure assessment and, if --pan-os-ver is provided, a self-reported version-based risk assessment.
The tool helps answer the following questions:
The tool checks whether the scanner host can establish a TCP connection to the specified target and port.
Example finding:
tcp=True
https=True
This means the target port is reachable from the scanner host and accepts HTTPS connections.
The tool sends safe HTTP(S) requests and records response status codes.
Example findings:
HTTPS HEAD /: HTTP/1.1 403 Forbidden
HTTPS GET /php/uid.php: HTTP/1.1 500 Internal Server Error
This means the service is reachable and is processing HTTP(S) requests.
The tool checks paths commonly associated with PAN-OS portal or response-page functionality.
Examples:
/php/login.php
/php/uid.php
/php/uidlogin.php
Non-404 responses from these paths may indicate that portal-related handlers are reachable from the scanner host.
The tool looks for lightweight textual indicators in response headers, titles, redirects, cookies, and response body samples.
Examples of indicators:
palo alto
pan-os
globalprotect
captive portal
user-id
authentication portal
response page
These indicators increase confidence that the exposed service is related to PAN-OS portal functionality.
If --pan-os-ver is provided, the tool compares the supplied version against the affected/fixed thresholds from the official advisory table embedded in the script.
Example:
--pan-os-ver 10.2.4-h2
Example result:
patch_status: AFFECTED_BY_VERSION
version_status: AFFECTED_VERSION
combined_risk=HIGH
If --pan-os-ver is not provided, the tool displays the affected/fixed version table and reports the version status as unknown.
This tool uses only Python standard library modules.
No external Python dependencies are required.
python3 --version
Recommended:
Python 3.8+
A minimal requirements.txt can be used:
# No external dependencies required.
# This tool uses only Python standard library modules.
python3 panos_cve_2026_0300_diag.py \
-t 172.16.20.254 \
-p 6082
python3 panos_cve_2026_0300_diag.py \
-t 172.16.20.254 \
-p 6082 \
--pan-os-ver 10.2.4-h2
python3 panos_cve_2026_0300_diag.py \
-t 172.16.20.254 \
-p 6082 \
--pan-os-ver 10.2.4-h2 \
--verbose
python3 panos_cve_2026_0300_diag.py \
-t 172.16.20.254 \
-p 6082 \
--scheme both
By default, the tool probes all safe known paths.
Use --minimal to check only:
//php/login.phppython3 panos_cve_2026_0300_diag.py \
-t 172.16.20.254 \
-p 6082 \
--minimal
python3 panos_cve_2026_0300_diag.py \
-t 172.16.20.254 \
-p 443,6082,6081-6083 \
--scheme both
python3 panos_cve_2026_0300_diag.py \
-t 172.16.20.0/24 \
-p 6082 \
--csv-out results.csv \
--json-out results.json
Create targets.txt:
172.16.20.254
172.16.20.253
172.16.21.0/24
Run:
python3 panos_cve_2026_0300_diag.py \
-T targets.txt \
-p 6082 \
--json-out results.json
| Option | Description |
|---|---|
-t, --target | Target IP, hostname, or CIDR. Comma-separated values are supported. |
-T, --targets-file | File containing targets, one per line. CIDR entries are supported. |
-p, --ports | Port or port range. Example: 6082, 443,6082, 6081-6083. |
--scheme | Probe scheme: https, http, or both. Default: https. |
--pan-os-ver | Self-reported PAN-OS version, such as 10.2.4-h2. |
--timeout | Socket timeout in seconds. Default: 4.0. |
--max-bytes | Maximum response bytes to read per request. Default: 16384. |
--minimal | Probe only / and /php/login.php. |
--verbose | Print all request observations. |
--quiet | Reduce console output. |
--json-out | Write full results to a JSON file. |
--csv-out | Write summary results to a CSV file. |
The tool produces three main types of assessment: