PT-2026-40754 · Palo Alto Networks · Pan-Os

CVE-2026-0257

·

Published

2026-05-13

·

Updated

2026-09-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PAN-OS versions prior to 10.2.7 PAN-OS version 10.2.8 PAN-OS version 10.2.9 PAN-OS version 10.2.10 PAN-OS version 10.2.11 Prisma Access (affected versions not specified)
Description Authentication bypass flaws in the GlobalProtect portal and gateway allow a remote, unauthenticated attacker to bypass security restrictions and establish unauthorized VPN connections. The issue stems from the use of authentication override cookies that lack proper validation of authenticity and integrity. When the Cloud Authentication Service (CAS) is disabled and authentication override cookies are enabled, attackers can manipulate these cookies by leveraging the public key of specific certificates used for encryption. This is achieved by including a specific HTTP form value in a POST request sent to the authentication endpoint, allowing the attacker to forge valid cookies that the server decrypts, resulting in an authentication bypass.
Real-world exploitation has been observed, including campaigns by a single threat actor using spoofed MAC addresses and the deployment of Qilin ransomware. In these incidents, attackers gained initial access via VPN, performed privilege escalation, dumped LSASS and NTDS databases for credential harvesting, and moved laterally using PsExec and RDP. Post-exploitation activities included the use of AnyDesk, Ngrok, and LogMeIn for persistent remote access, and the exfiltration of data to cloud storage before encrypting files.
Recommendations Apply the relevant patches provided by Palo Alto Networks for PAN-OS versions prior to 10.2.7, 10.2.8, 10.2.9, 10.2.10, and 10.2.11. Apply the relevant patches provided by Palo Alto Networks for Prisma Access. As a temporary mitigation, disable the use of authentication override cookies in the GlobalProtect service.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07261
CVE-2026-0257
PANOS_CVE2026_0257

Affected Products

Pan-Os