Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0257 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257 | US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
History
01 Jun 2026, 12:33
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257 - US Government Resource |
29 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://security.paloaltonetworks.com/CVE-2026-0257 - Vendor Advisory | |
| CPE | cpe:2.3:o:paloaltonetworks:pan-os:11.1.11:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h15:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.0:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h12:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.5:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.2:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h16:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h11:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.7:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.15:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h12:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h8:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h6:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h9:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.13:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h10:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.0:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h24:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.13:h3:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_access:-:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h12:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h10:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.4:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.7:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h8:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h30:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h18:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.18:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h13:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.13:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.12:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.13:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h12:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h22:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h8:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.16:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.1:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.4:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h25:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.2:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h15:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h18:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h21:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h32:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h27:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h21:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.4:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h17:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.3:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h9:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.16:h6:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h32:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.5:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.14:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h13:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h10:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h14:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.7:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h10:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h10:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.3:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h18:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h29:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.4:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h21:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h14:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h18:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h17:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h20:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h11:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h7:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h6:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h6:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h12:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.18:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.8:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h21:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h27:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.6:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.7:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.8:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.16:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h14:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h3:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.14:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.18:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h10:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h1:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.16:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:12.1.6:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.11:-:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h2:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h19:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.10:h6:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h31:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h16:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.17:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h23:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.7:h4:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h9:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h25:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.10:h5:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.9:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h9:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.9:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.5:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h19:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h16:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:h17:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:11.2.1:*:*:*:*:*:*:* |
|
| First Time |
Paloaltonetworks prisma Access
Paloaltonetworks Paloaltonetworks pan-os |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
13 May 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 19:17
Updated : 2026-06-01 12:33
NVD link : CVE-2026-0257
Mitre link : CVE-2026-0257
CVE.ORG link : CVE-2026-0257
JSON object : View
Products Affected
paloaltonetworks
- prisma_access
- pan-os
CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checking
