Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Palo Alto Networks — Cloud NGFW
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
9.8
31.7%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- May 6, 2026
- Modified
- Jun 17, 2026
- Added to KEV
- May 6, 2026
- Federal patch due
- May 9, 2026
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2026-0300, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- p3Nt3st3r-sTAr/CVE-2026-0300-POC★ 21
updated Jul 13, 2026
- matad0r-maghribi/CVE-2026-0300-PANOS★ 3
Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.
updated Aug 25, 2026
- qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC★ 3
A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™ Authentication Portal (CWE-787).
updated Aug 21, 2026
- ridhinva/panos-captive-portal-rce★ 2
Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls (CISA KEV 2026-05-13)
updated Aug 10, 2026
- mr-r3b00t/CVE-2026-0300★ 1
a honeypot for CVE-2026-0300
updated Aug 25, 2026
- shizuku198411/CVE-2026-0300★ 1
PAN-OS CVE-2026-0300 Non-Destructive Exposure Survey Tool
updated Jul 10, 2026
- 0xBlackash/CVE-2026-0300★ 0
CVE-2026-0300
updated Aug 25, 2026
- sam00/POC-CVE-2026-0300-exploit★ 0
Palo Alto - CVE-2026-0300 exploit
updated Aug 6, 2026
References
Frequently asked questions
What is CVE-2026-0300?
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
How severe is CVE-2026-0300?
CVE-2026-0300 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2026-0300 actively exploited in the wild?
Yes. CVE-2026-0300 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 6, 2026, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2026-0300?
31.7% - meaning FIRST.org's EPSS model estimates a 31.7% probability this vulnerability will be exploited in the wild within 30 days (98% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2026-0300?
We found 8 public GitHub repositories referencing CVE-2026-0300, though none matched a known Nuclei template or Metasploit module at last check. Review each one before relying on it - see the proof-of-concept section above.
What type of vulnerability is CVE-2026-0300?
CVE-2026-0300 is classified under CWE-787 (CWE-787: Out-of-bounds Write).
Cross-checked against
Impactr finds and proves whether CVE-2026-0300 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist