{"id":"CVE-2026-0300","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-0300","summary":"A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute…","details":"A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. \n\nThe risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.\n\nPrisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.","published":"2026-05-06T19:16:35.730","modified":"2026-06-17T10:10:43.073","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.31725,"percentile":0.98177,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.paloaltonetworks.com/CVE-2026-0300"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/html/ssa-967325.html"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T10:10:43.073"}}