PT-2026-40754 · Palo Alto Networks · Pan-Os
CVE-2026-0257
·
Published
2026-05-13
·
Updated
2026-09-10
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PAN-OS versions prior to 10.2.7
PAN-OS version 10.2.8
PAN-OS version 10.2.9
PAN-OS version 10.2.10
PAN-OS version 10.2.11
Prisma Access (affected versions not specified)
Description
Authentication bypass flaws in the GlobalProtect portal and gateway allow a remote, unauthenticated attacker to bypass security restrictions and establish unauthorized VPN connections. The issue stems from the use of authentication override cookies that lack proper validation of authenticity and integrity. When the Cloud Authentication Service (CAS) is disabled and authentication override cookies are enabled, attackers can manipulate these cookies by leveraging the public key of specific certificates used for encryption. This is achieved by including a specific HTTP form value in a POST request sent to the authentication endpoint, allowing the attacker to forge valid cookies that the server decrypts, resulting in an authentication bypass.
Real-world exploitation has been observed, including campaigns by a single threat actor using spoofed MAC addresses and the deployment of Qilin ransomware. In these incidents, attackers gained initial access via VPN, performed privilege escalation, dumped LSASS and NTDS databases for credential harvesting, and moved laterally using PsExec and RDP. Post-exploitation activities included the use of AnyDesk, Ngrok, and LogMeIn for persistent remote access, and the exfiltration of data to cloud storage before encrypting files.
Recommendations
Apply the relevant patches provided by Palo Alto Networks for PAN-OS versions prior to 10.2.7, 10.2.8, 10.2.9, 10.2.10, and 10.2.11.
Apply the relevant patches provided by Palo Alto Networks for Prisma Access.
As a temporary mitigation, disable the use of authentication override cookies in the GlobalProtect service.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os