BlackTree Security · Infrastructure · Automation · AI

The Firewall’s Authentication Portal Became a Path to Root

Palo Alto Networks disclosed that attackers were already exploiting CVE-2026-0300 when the company published its advisory on 5 May 2026. The flaw sits in the PAN-OS User-ID Authentication Portal, also known as the Captive Portal, and can let an unauthenticated remote attacker execute code with root privileges on an affected firewall.

This is not simply another bug in a management interface. The vulnerable service is part of the device intended to enforce identity-aware network policy. When that boundary is exposed to an untrusted network, a specially crafted packet can turn an authentication control into an entry point with the highest local privilege.

The exploit path is narrow, but the outcome is complete

Palo Alto Networks rates the vulnerability critical and says it was discovered in production use. The company describes an out-of-bounds write in the User-ID Authentication Portal. Successful exploitation requires no account, no user interaction and low attack complexity. The result is arbitrary code execution as root on PA-Series and VM-Series firewalls.

Exposure depends on two configuration conditions being present at the same time. The User-ID Authentication Portal must be enabled, and an interface management profile with response pages enabled must be attached to a Layer 3 interface where internet or other untrusted traffic can arrive. Palo Alto Networks says Prisma Access, Cloud NGFW and Panorama are not affected.

  • Attack vector: network
  • Authentication: none required
  • User interaction: none
  • Impact: arbitrary code execution with root privileges
  • Observed activity: limited exploitation against portals exposed to untrusted addresses or the public internet
  • CISA status: added to the Known Exploited Vulnerabilities catalogue on 6 May, with an initial federal remediation deadline of 9 May

A security appliance is also a concentrated trust target

Firewalls sit in a particularly dangerous position when compromised. They terminate or mediate remote access, see traffic from multiple trust zones and often hold credentials, certificates, routing information and policy data. Root access on the appliance therefore changes the response question from “is the portal vulnerable?” to “can the organisation still trust the control point?”

That distinction matters because installing a fixed build closes the known entry path but does not prove the device was untouched. Organisations that exposed the vulnerable configuration during the exploitation window should preserve relevant logs, review administrative and configuration activity, investigate unexpected processes or changes, and assess whether credentials and tokens available to the device need to be replaced.

The final patch matrix is broad

The vendor released fixes across supported PAN-OS branches. Administrators should use the exact matrix in the Palo Alto Networks advisory, because the safe release differs by maintenance train. Fixed destinations include PAN-OS 12.1.4-h5 or 12.1.7, 11.2.4-h17, 11.2.7-h13, 11.2.10-h6 or 11.2.12, 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5 or 11.1.15, and 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7 or 10.2.18-h6.

Unsupported PAN-OS releases must move to a supported fixed version. The advisory was updated through 28 May, so operators working from an early copy should recheck the current guidance rather than relying on the initial staggered release schedule.

Mitigation is configuration work, not a substitute for the update

Where an immediate upgrade is impossible, Palo Alto Networks recommends restricting the User-ID Authentication Portal to trusted zones and disabling response pages on every interface management profile attached to an interface that receives untrusted traffic. The portal should be disabled entirely when it is not needed.

Customers with a Threat Prevention subscription can also enable Threat ID 510019 from Applications and Threats content version 9097-10022. That protection requires PAN-OS 11.1 or later. It is an additional control, not evidence that an exposed device was never reached.

What defenders should do now

  1. Identify every PA-Series and VM-Series firewall running a potentially affected PAN-OS build.
  2. Verify whether the User-ID Authentication Portal and response-page configuration created exposure from an untrusted zone.
  3. Upgrade to the fixed release for the deployed maintenance train.
  4. Restrict the portal to trusted internal addresses or disable it where it is not operationally required.
  5. Review the device as a possible incident if the vulnerable service was internet-facing before remediation.
  6. Reassess credentials, certificates and trust relationships reachable from the appliance if compromise cannot be ruled out.

The enduring lesson is architectural. A service that helps a firewall identify users can itself become an unauthenticated path to root when it is exposed beyond its intended trust boundary. Configuration reduced the population at risk, but active exploitation removed any justification for treating the issue as routine maintenance.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *