Evidence dossier
CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-IDTM Authentication Portal
Exploited in the wild (CISA KEV since May 6, 2026). palo_alto reports CVSS 4.0 8.7. Severity assessments differ within at least one CVSS version. EPSS estimates 31.7% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A buffer overflow vulnerability in the User-IDTM Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-IDTM Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
- State
- PUBLISHED
- Published
- May 6, 2026
- Updated
- Jul 14, 2026
- Evidence coverage
- 87%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCApalo_altoOriginal evidence ↗
Record text: PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Inspect raw assertion
- Field
container- Value
- PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
- Source dateSource date omittedFirst observed by CASCAsiemens-SADPOriginal evidence ↗
Record text: Container present
Inspect raw assertion
- Field
container- Value
- Container present
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 31.72% probability · 98.16th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.317250000000; percentile 0.981620000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date May 6, 2026 · first observed Jul 19, 2026
FIRST EPSS · score date Aug 27, 2026 · 98.2th percentile · first observed Aug 27, 2026
palo_alto · CVSS 4.0 · first observed Jul 19, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Inspect raw assertion
- Field
container- Value
- PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Container present
Inspect raw assertion
- Field
container- Value
- Container present
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
31.72% probability · 98.16th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.317250000000; percentile 0.981620000000
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
54 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "All", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "12.1.0", "lessThan": "12.1.7", "versionType": "custom"}, {"status": "affected", "version": "11.2.0", "lessThan": "11.2.12", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.15", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.18-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "All", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "lessThan": "*", "versionType": "custom"}]product-d0b149a5a89511d26f020af1f2ed30cd4cb2276c017038f28664b4164c75d74aLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-1410:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0183bab-b1ae-44d9-b187-798cecb9a640
product-56c0af07849788c85668dc877d31af8e623dadf6612a711d06c3dfb2ff46f884Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-1420:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8b2fcf34-ec08-4af2-ac0b-d48d97bffc86
product-7bc813fb3d492b04720adab6c9f1d51bf39e927157bc23d232cf0b22d57ab049Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-3410:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
08bd8f1c-5cda-4b5c-9da6-967773a9b0ee
product-1fe1665933992b5f99df582045812789078728448bee5c9c740980fdd33a6a11Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-3420:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
824ee71f-d617-4fda-b529-dcf8f6ba5c1b
product-9e88e00efd1300300f8f045ba635e1f2ffefc8c1a9f8d67c7d503c6daacf148bLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-3430:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d2da44a2-3859-48b8-8146-4433d5ff4c68
product-c91bf5ac4179c0504780020902ce510a7e923b36049a37142db5867db0e9d7fdLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-3440:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1ff7be07-98f5-4db7-ad77-625bb46cfc3c
product-782c2ba45bf4ce473858a2c63a9acbb6bfe1e230aacc3b17f5ece5bb2a49aafaLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-410:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
babab43b-198c-42e0-836c-f7fb30256a2f
product-05453eb4140d3dbdeeff09b18b709825a0e7b2b3f773db0bb6b9ba2a9613dd43Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-410r:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4df6f082-99cc-47bb-aeb1-2fd00ee1278d
product-ba9a3935785066b214bd25458d3f4633ddc05505a007a13e7116feae04c7254bLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-410r-5g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa9d11d5-fdea-4b83-8ae2-64a007791cba
product-dd61f1d6226400a58cdedcb213987d8485b56520c6ecd87c5e42c214e9ff0442Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-415:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0ba207f-6cdf-4d90-8739-8fe34ec0f3c4
product-654c48d5daba083f6e056d2074551e52165605fec4bf732795683613cea6a200Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-415-5g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
38dc5e80-274a-4e65-a2dc-bc79623bf698
product-7dfecfc33e939b3dde2a8692c736474a7815d876fa871a961e55089cc58506f8Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-440:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
31854314-2abe-4658-ad1b-230a0b261674
product-5eb03af8d9c954c79ba57ac826893f1646babb3d49258cf2924986b83d8c7131Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-445:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8ca7e681-be00-416c-86c5-08a1a18976f4
product-6557b9e10f14c19dc8f16a2e42e658834464e41496d831f0fbf937568a67e53eLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-450:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f5128449-d0a7-47fa-afe7-258672972bbf
product-0a4341fef062f45487e02e23a105320a5811a2d1ce55e33cf76f1ced3e41090cLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-450r:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6db8d540-4f7a-44f2-9f5b-96f1f704330a
product-bc1fbb7da65882fb50b6c8adfdfa0e5f3820847051a3240178330731cf610f47Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-450r-5g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb12277d-b9cf-4703-b08f-5555261f1bc4
product-f8df77812d1249e27da11e71bda6c21099f2867ac05aa914369f6ab12e025823Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-455:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
85b9e8ef-5a4e-40b7-8044-c4352ad1bd2e
product-22d0ecc287374ea5b5bd3e9ba497f1ed573cec686fda5f080f1200eac69a5e89Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-455-5g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fe7143c5-fdef-4440-ab43-9a6b5d201d57
product-1939af157d3acace75a406778712854add746df7114ffaf67285d314f749641eLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-455r-5g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
befb32d5-43c7-4d4a-aa81-7bbc006b92cc
product-8c2c6b98a904dea558f1d586dc9c7c86323772d3185e3b91358558fb1879966bLinked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-460:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
017a0571-e011-4ae6-b4ed-b1aac0eba22b
product-e9f6c4060549ba17e2d7af4f89ec027a15084f40f801768867b266d002699143Linked exactInspect raw assertion
cpe:2.3:h:paloaltonetworks:pa-501:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb469dd8-c776-4b6a-91a4-66b27483fde8
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:RedCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:RedCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:RedEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.