Evidence dossier

CVE-2026-0300

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-IDTM Authentication Portal

Exploited in the wild (CISA KEV since May 6, 2026). palo_alto reports CVSS 4.0 8.7. Severity assessments differ within at least one CVSS version. EPSS estimates 31.7% exploit likelihood as of Aug 27, 2026.

77.281.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A buffer overflow vulnerability in the User-IDTM Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-IDTM Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

State
PUBLISHED
Published
May 6, 2026
Updated
Jul 14, 2026
Evidence coverage
87%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    palo_alto

    Record text: PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

    Inspect raw assertion
    Field
    container
    Value
    PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    siemens-SADP

    Record text: Container present

    Inspect raw assertion
    Field
    container
    Value
    Container present
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 31.72% probability · 98.16th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.317250000000; percentile 0.981620000000
    Original evidence ↗

Assessments differ

NVD9.8CVSS 3.1 · source date omitted
psirt@paloaltonetworks.com9.3CVSS 4.0 · source date omitted

Values are shown separately by source and CVSS version.

ExploitationCatalog member

CISA KEV · catalog date May 6, 2026 · first observed Jul 19, 2026

Exploit likelihood31.72%

FIRST EPSS · score date Aug 27, 2026 · 98.2th percentile · first observed Aug 27, 2026

SeverityAssessments differ

palo_alto · CVSS 4.0 · first observed Jul 19, 2026 · values shown separately below

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
palo_altoOriginal assertion
Record text

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

Inspect raw assertion
Field
container
Value
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
siemens-SADPSource-declared origin
Record text

Container present

Inspect raw assertion
Field
container
Value
Container present
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

31.72% probability · 98.16th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.317250000000; percentile 0.981620000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
211Underlying assertions
50Canonical products
163Target assertions
48Constraint assertions

Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

54 scope groups

palo_alto · source assertedPalo Alto NetworksCloud NGFWDirect source scope
Unaffected: All (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "All", "versionType": "custom"}]
palo_alto · source assertedPalo Alto NetworksPAN-OSDirect source scope
Affected: 12.1.0 to before 12.1.7 (custom comparison)Affected: 11.2.0 to before 11.2.12 (custom comparison)Affected: 11.1.0 to before 11.1.15 (custom comparison)Affected: 10.2.0 to before 10.2.18-h6 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "12.1.0", "lessThan": "12.1.7", "versionType": "custom"}, {"status": "affected", "version": "11.2.0", "lessThan": "11.2.12", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.15", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.18-h6", "versionType": "custom"}]
palo_alto · source assertedPalo Alto NetworksPrisma AccessDirect source scope
Unaffected: All (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "All", "versionType": "custom"}]
siemens-SADP · source assertedSiemensRUGGEDCOM APE1808Direct source scope
Affected: 0 to before * (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "*", "versionType": "custom"}]
NVD CPE · HARDWAREpaloaltonetworkspa-1410Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d0b149a5a89511d26f020af1f2ed30cd4cb2276c017038f28664b4164c75d74aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-1410:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0183bab-b1ae-44d9-b187-798cecb9a640
NVD CPE · HARDWAREpaloaltonetworkspa-1420Environmental constraint · 1 assertions
Version not applicableCanonical identity product-56c0af07849788c85668dc877d31af8e623dadf6612a711d06c3dfb2ff46f884Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-1420:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b2fcf34-ec08-4af2-ac0b-d48d97bffc86
NVD CPE · HARDWAREpaloaltonetworkspa-3410Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7bc813fb3d492b04720adab6c9f1d51bf39e927157bc23d232cf0b22d57ab049Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-3410:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    08bd8f1c-5cda-4b5c-9da6-967773a9b0ee
NVD CPE · HARDWAREpaloaltonetworkspa-3420Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1fe1665933992b5f99df582045812789078728448bee5c9c740980fdd33a6a11Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-3420:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    824ee71f-d617-4fda-b529-dcf8f6ba5c1b
NVD CPE · HARDWAREpaloaltonetworkspa-3430Environmental constraint · 1 assertions
Version not applicableCanonical identity product-9e88e00efd1300300f8f045ba635e1f2ffefc8c1a9f8d67c7d503c6daacf148bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-3430:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d2da44a2-3859-48b8-8146-4433d5ff4c68
NVD CPE · HARDWAREpaloaltonetworkspa-3440Environmental constraint · 1 assertions
Version not applicableCanonical identity product-c91bf5ac4179c0504780020902ce510a7e923b36049a37142db5867db0e9d7fdLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-3440:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ff7be07-98f5-4db7-ad77-625bb46cfc3c
NVD CPE · HARDWAREpaloaltonetworkspa-410Environmental constraint · 1 assertions
Version not applicableCanonical identity product-782c2ba45bf4ce473858a2c63a9acbb6bfe1e230aacc3b17f5ece5bb2a49aafaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-410:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    babab43b-198c-42e0-836c-f7fb30256a2f
NVD CPE · HARDWAREpaloaltonetworkspa-410rEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-05453eb4140d3dbdeeff09b18b709825a0e7b2b3f773db0bb6b9ba2a9613dd43Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-410r:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4df6f082-99cc-47bb-aeb1-2fd00ee1278d
NVD CPE · HARDWAREpaloaltonetworkspa-410r-5gEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ba9a3935785066b214bd25458d3f4633ddc05505a007a13e7116feae04c7254bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-410r-5g:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa9d11d5-fdea-4b83-8ae2-64a007791cba
NVD CPE · HARDWAREpaloaltonetworkspa-415Environmental constraint · 1 assertions
Version not applicableCanonical identity product-dd61f1d6226400a58cdedcb213987d8485b56520c6ecd87c5e42c214e9ff0442Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-415:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0ba207f-6cdf-4d90-8739-8fe34ec0f3c4
NVD CPE · HARDWAREpaloaltonetworkspa-415-5gEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-654c48d5daba083f6e056d2074551e52165605fec4bf732795683613cea6a200Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-415-5g:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    38dc5e80-274a-4e65-a2dc-bc79623bf698
NVD CPE · HARDWAREpaloaltonetworkspa-440Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7dfecfc33e939b3dde2a8692c736474a7815d876fa871a961e55089cc58506f8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-440:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    31854314-2abe-4658-ad1b-230a0b261674
NVD CPE · HARDWAREpaloaltonetworkspa-445Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5eb03af8d9c954c79ba57ac826893f1646babb3d49258cf2924986b83d8c7131Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-445:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ca7e681-be00-416c-86c5-08a1a18976f4
NVD CPE · HARDWAREpaloaltonetworkspa-450Environmental constraint · 1 assertions
Version not applicableCanonical identity product-6557b9e10f14c19dc8f16a2e42e658834464e41496d831f0fbf937568a67e53eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-450:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f5128449-d0a7-47fa-afe7-258672972bbf
NVD CPE · HARDWAREpaloaltonetworkspa-450rEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0a4341fef062f45487e02e23a105320a5811a2d1ce55e33cf76f1ced3e41090cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-450r:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6db8d540-4f7a-44f2-9f5b-96f1f704330a
NVD CPE · HARDWAREpaloaltonetworkspa-450r-5gEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-bc1fbb7da65882fb50b6c8adfdfa0e5f3820847051a3240178330731cf610f47Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-450r-5g:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb12277d-b9cf-4703-b08f-5555261f1bc4
NVD CPE · HARDWAREpaloaltonetworkspa-455Environmental constraint · 1 assertions
Version not applicableCanonical identity product-f8df77812d1249e27da11e71bda6c21099f2867ac05aa914369f6ab12e025823Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-455:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    85b9e8ef-5a4e-40b7-8044-c4352ad1bd2e
NVD CPE · HARDWAREpaloaltonetworkspa-455-5gEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-22d0ecc287374ea5b5bd3e9ba497f1ed573cec686fda5f080f1200eac69a5e89Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-455-5g:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fe7143c5-fdef-4440-ab43-9a6b5d201d57
NVD CPE · HARDWAREpaloaltonetworkspa-455r-5gEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-1939af157d3acace75a406778712854add746df7114ffaf67285d314f749641eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-455r-5g:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    befb32d5-43c7-4d4a-aa81-7bbc006b92cc
NVD CPE · HARDWAREpaloaltonetworkspa-460Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8c2c6b98a904dea558f1d586dc9c7c86323772d3185e3b91358558fb1879966bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-460:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    017a0571-e011-4ae6-b4ed-b1aac0eba22b
NVD CPE · HARDWAREpaloaltonetworkspa-501Environmental constraint · 1 assertions
Version not applicableCanonical identity product-e9f6c4060549ba17e2d7af4f89ec027a15084f40f801768867b266d002699143Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:paloaltonetworks:pa-501:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb469dd8-c776-4b6a-91a4-66b27483fde8

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
psirt@paloaltonetworks.comCVSS 4.0 · role Secondary · priority eligiblevalid_matchCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red
9.3
palo_altoCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red
8.7
palo_altoCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.