CVE-2026-0300: critical PAN-OS portal root RCE flaw
CVE-2026-0300 enables unauthenticated root RCE in a specific PAN-OS Authentication Portal configuration. Check exposure, patches and mitigations.
- AUTHOR
- Karol Rapacz / Penetration Tester (OSCP, PNPT)
- PUBLISHED
- 10 July 2026
- READING TIME
- 9 min read
- TOPIC
- Vulnerabilities
CVE-2026-0300 is a critical buffer overflow in the PAN-OS User-ID Authentication Portal, also called Captive Portal. In an affected configuration, an unauthenticated network attacker can execute code as root on PA-Series or VM-Series firewalls. Palo Alto Networks rated it CVSS 9.3 and confirmed limited exploitation.
Not every PAN-OS deployment is exposed. Two configuration conditions must exist together, so response begins by checking reachability and configuration rather than labelling every Palo Alto product vulnerable.
What the vendor confirmed
The Palo Alto Networks advisory describes crafted packets causing arbitrary root code execution without credentials or user interaction. The vendor observed limited exploitation against portals reachable from untrusted addresses or the public internet.
CERT-EU confirms the CVSS 9.3 rating and PA-Series/VM-Series impact. CISA added the issue to KEV.
Two required exposure conditions
The scenario applies when both are true:
- User-ID Authentication Portal is enabled under
Device > User Identification > Authentication Portal Settings; and - an interface-management profile with Response Pages enabled is assigned to an L3 interface in a zone reachable from the internet or another untrusted network.
The condition covers transparent and redirect modes. A portal available only from a trusted internal network has a different exposure. Prisma Access, Cloud NGFW and Panorama are not affected by CVE-2026-0300.
Selecting the correct fixed release
There is no universal patch number for every PAN-OS branch. The vendor’s Solution table identifies fixed releases, including:
- 12.1: 12.1.4-h5 or 12.1.7 and later;
- 11.2: 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, or 11.2.12 and later;
- 11.1: branch-specific hotfixes including 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, or 11.1.15 and later;
- 10.2: 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, or 10.2.18-h6 and later.
Use the exact vendor table for the installed branch. Unsupported releases must move to a supported fixed version.
Immediate actions
- Inventory PA-Series and VM-Series appliances, versions and owners.
- Check both exposure conditions on every firewall.
- Install the exact fixed release from the vendor table.
- Until patching, restrict the portal to trusted zones and disable Response Pages on untrusted interfaces.
- Disable Authentication Portal entirely if the function is unused.
- After changes, test authentication and confirm externally that the portal is no longer exposed where it should not be.
Customers with Threat Prevention can block attempts using Threat ID 510019, available from Applications and Threats 9097-10022. Because of decoder requirements it needs PAN-OS 11.1 or later. Verify that the content update and blocking profile are actually active. The signature is defence in depth, not a patch replacement.
Investigating prior exposure
For an exposed vulnerable portal, review threat logs, portal traffic, restarts and configuration changes. Look for new administrators, policy modifications, unexpected outbound connections and disabled controls. These signals are not automatic proof of this CVE, but they justify controlled incident analysis.
CVE-2026-0300 enables unauthenticated root RCE only under the stated PA-Series/VM-Series conditions. Verify both, apply the branch-specific fix and review prior exposure. Do not incorrectly include Prisma Access, Cloud NGFW or Panorama.
Sources: Palo Alto Networks advisory, CERT-EU 2026-006, CISA KEV.


