Sploitus

Exploit for CVE-2026-0300

cve · 2026-05-06

Exploit Code

MARKDOWN6 lines
## https://sploitus.com/exploit?id=CVE-2026-0300
A buffer overflow vulnerability in the User-IDâ„¢ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. 

The risk of this issue is greatly reduced if you secure access to the User-IDâ„¢ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.

Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.