HarborGuard / CVE
Back to search
HIGHCVE-2026-0257Published Modified CNA palo_alto

CVE-2026-0257: PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Metrics

CVSS v4.0
7.8
Severity
HIGH
Fixed in
10.2.10-h36
Affected Products
3

Fix available

10.2.10-h3610.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h3411.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h3311.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h1711.2.7-h1312.1.7, 12.1.4-h6All
Affected packages
  • Palo Alto Networks / Cloud NGFW
    Fixed in All
  • Palo Alto Networks / PAN-OS
    < 12.1.7, 12.1.4-h6 (from 12.1.0) · < 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17 (from 11.2.0) · < 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33 (from 11.1.0) · < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34 (from 10.2.0)
  • Palo Alto Networks / Prisma Access
    < 10.2.10-h36 (from 10.2.0) · < 11.2.7-h13 (from 11.2.0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red