Improper Verification of Cryptographic Signature in Palo Alto PAN-OS - CVE-2026-0265
Published: May 19, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication controls.
The vulnerability exists due to improper verification of cryptographic signature in the Cloud Authentication Service (CAS) authentication mechanism when handling authentication requests on a login interface with CAS enabled. A remote attacker can send a crafted authentication request to bypass authentication controls.
The risk is higher when CAS is enabled on the management interface.