Sploitus

CVE-2026-0257

19 known exploits for CVE-2026-0257

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Affected products
Pan-Os
Paloaltonetworks Pan-os
< 10.2.7, 10.2.8, 10.2.9, 10.2.10, 10.2.11, 10.2.12, 10.2.13, 10.2.14, 10.2.15, 10.2.16, 10.2.17, 10.2.18, 11.1.0, 11.1.1, 11.1.2, 11.1.3, 11.1.4, 11.1.5, 11.1.6, 11.1.7, 11.1.8, 11.1.9, 11.1.10, 11.1.11, 11.1.12, 11.1.13, 11.1.14, 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 11.2.5, 11.2.6, 11.2.7, 11.2.8, 11.2.9, 11.2.10, 11.2.11, 12.1.2
CVSS 3.1
9.1 CRITICAL
EPSS
93.9% (100th percentile)
Weakness
CWE-565
NVD status
Analyzed
Published
2026-05-13
Attack patterns
CAPEC-114
Entry point
user request body
Path
/ssl-vpn/login.esp

Fix

Note: With this fix, if the firewall is configured to use an authentication override cookie for the GlobalProtect Portal or Gateway, it will regenerate the cookie using a more secure method. Therefore, GP users will need to re-authenticate after a PAN-OS upgrade, even if a valid cookie is present. This is a one time requirement. Once they re-authenticate after the upgrade, the authentication override cookie and its validity will work as they do today.

CVE-2026-0257 at NVD
Authoritative description, scoring and affected products

19 known exploits for CVE-2026-0257

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2026-0257
2026-08-26 KitPloitKITPLOIT
CVE-2026-0257
2026-08-26 KitPloitKITPLOIT
CVE-2026-0257
2026-08-26 KitPloitKITPLOIT
CVE-2026-0257
2026-08-26 KitPloitKITPLOIT
CVE-2026-0257
2026-08-26 KitPloitKITPLOIT
CVE-2026-0257-PoC
2026-08-25 KitPloitKITPLOIT
CVE-2026-0257
2026-08-24 KitPloitKITPLOIT
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-07-08 amnsecurityGITHUB
📄 PAN-OS GlobalProtect Authentication Bypass
2026-07-07 indoushkaPACKETSTORM
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-06-15 Ez4rd1x1GITHUB
📄 Palo Alto GlobalProtect Authentication Bypass
2026-06-12 indoushkaPACKETSTORMRuby
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-06-10 grayxploitGITHUB
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-06-09 jenniferreire26GITHUB
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-06-03 tushargurav28GITHUB
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-06-01 jennydokumi30GITHUB
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-06-01 bolubeyGITHUB
Exploit for Reliance on Cookies without Validation and Integrity Checking in Paloaltonetworks Pan-Os
2026-05-30 0xBlackashGITHUB
Exploit for CVE-2026-0257
2026-05-29 akashsingh0454GITHUB
CVE-2026-0257
2026-05-13 palo_altoUNKNOWN