Out-of-bounds write in Palo Alto PAN-OS - CVE-2026-0300
Published: May 6, 2026 / Updated: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within the User-ID Authentication Portal (aka Captive Portal) service. A remote attacker can send specially crafted packets to the device, trigger an out-of-bounds write and execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-0300
Links to Public Exploits and PoC-codes
- Exploit #12891 - panos-captive-portal-rce (Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls (CISA KEV 2026-05-13)) (August 14, 2026)
- Exploit #12724 - CVE-2026-0300-PANOS (Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.) (May 22, 2026)