PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
- Severity
- Critical9.8CVSS 3.1, Critical
- EPSS
- 32%
- Published
- 6 May 2026
- Updated
- 14 Jul 2026
Description
Title, description and vendor guidance are quoted from the source records.
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Weakness: CWE-787
Known exploited
Added to CISA KEV on 6 May 2026
Federal remediation due date: 9 May 2026
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
Exploit prediction
32% probability of exploitation in the next 30 days (percentile 98%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the source states, per branch
Versions matched by Patcharo
Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| 12.1 | >= 12.1.0, < 12.1.4-h5 >= 12.1.5, < 12.1.7 | 12.1.4-h5 12.1.7 |
| 11.2 | >= 11.2.0, < 11.2.4-h17 >= 11.2.5, < 11.2.7-h13 >= 11.2.8, < 11.2.10-h6 >= 11.2.11, < 11.2.12 | 11.2.4-h17 11.2.7-h13 11.2.10-h6 11.2.12 |
| 11.1 | >= 11.1.0, < 11.1.4-h33 >= 11.1.5, < 11.1.6-h32 >= 11.1.7, < 11.1.7-h6 >= 11.1.8, < 11.1.10-h25 >= 11.1.11, < 11.1.13-h5 >= 11.1.14, < 11.1.15 | 11.1.4-h33 11.1.6-h32 11.1.7-h6 11.1.10-h25 11.1.13-h5 11.1.15 |
| 10.2 | >= 10.2.0, < 10.2.7-h34 >= 10.2.8, < 10.2.10-h36 >= 10.2.11, < 10.2.13-h21 >= 10.2.14, < 10.2.16-h7 >= 10.2.17, < 10.2.18-h6 | 10.2.7-h34 10.2.10-h36 10.2.13-h21 10.2.16-h7 10.2.18-h6 |
Versions not listed are stated unaffected by the vendor.
Workaround / Vendor remediation
Workaround · PAN-OS
Customers can mitigate the risk of this issue by taking either of the following actions: * Restrict User-ID™ Authentication Portal access to only trusted zones and in addition, disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress. Keep Response Pages enabled only on interfaces in trust/internal zones where legitimate users' browsers ingress. Refer to Step 6 of the following Live Community article (https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-management-interface/ta-p/1001286) and Knowledgebase article (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC) for steps to restrict access. * Disable User-ID™ Authentication Portal if not required. Customers with a Threat Prevention subscription can block attacks for this vulnerab…
Vendor remediation · PAN-OS
This issue will be fixed in upcoming releases of PAN-OS as captured in the table above. We strongly recommend that you secure access to your User-ID™ Authentication Portal following the instructions in the workarounds section below.
References
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC