Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

Published 5 Aug 2026Updated 5 Aug 202612 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

Affected versions

PAN-OS: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoCA research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™ Authentication Portal (CWE-787).★ 3qassam-3152026-05-06CandidatePoC-in-GitHub · mr-r3b00t/CVE-2026-0300a honeypot for CVE-2026-0300★ 1mr-r3b00t2026-05-06CandidatePoC-in-GitHub · 0xBlackash/CVE-2026-0300CVE-2026-0300★ 00xBlackash2026-05-06CandidatePoC-in-GitHub · TailwindRG/cve-2026-0300-auditRead-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)★ 0TailwindRG2026-05-06CandidatePoC-in-GitHub · matad0r-maghribi/CVE-2026-0300-PANOSSecurity Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.★ 4matad0r-maghribi2026-05-06CandidatePoC-in-GitHub · shizuku198411/CVE-2026-0300PAN-OS CVE-2026-0300 Non-Destructive Exposure Survey Tool★ 1shizuku1984112026-05-06CandidatePoC-in-GitHub · p3Nt3st3r-sTAr/CVE-2026-0300-POC★ 22p3Nt3st3r-sTAr2026-05-06CandidatePoC-in-GitHub · lu4m575/CVE-2026-0300CVE-2026-0300 PAN-OS 12.1, 11.2, 11.1, 10.2★ 0lu4m5752026-05-21CandidatePoC-in-GitHub · ridhinva/panos-captive-portal-rceScanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls (CISA KEV 2026-05-13)★ 2ridhinva2026-05-22CandidatePoC-in-GitHub · sam00/POC-CVE-2026-0300-exploitPalo Alto - CVE-2026-0300 exploit★ 0sam002026-08-06Candidate