Junglewise Threat Intelligence

CVE-2026-0265: Palo Alto Networks PAN-OS authentication bypass in Cloud Authentication Service

CVE-2026-0265 · Severity: info · CVSS 7.2 · Published 2026-05-13

Technologies: Siemens RUGGEDCOM APE1808 Virtual NGFW. Vendors: Palo Alto Networks, Siemens.

Executive brief

A security vulnerability has been identified in Palo Alto Networks PAN-OS software, which powers many corporate firewalls and network security management systems. If the Cloud Authentication Service (CAS) is enabled, an unauthorized person could bypass security checks to gain access to the system. This could allow an attacker to take control of the firewall, potentially leading to data theft or significant network disruptions. The risk is highest for organizations that have their management interface exposed to the internet.

Technical details

An authentication bypass vulnerability (CWE-347) exists in Palo Alto Networks PAN-OS due to improper verification of cryptographic signatures when the Cloud Authentication Service (CAS) is utilized. An unauthenticated attacker with network access to a login interface (such as the management web interface, GlobalProtect Portal, or GlobalProtect Gateway) can bypass authentication controls if a CAS-enabled Authentication Profile is active. The vulnerability is most critical when the management interface is accessible over the network. Exploitation allows for full compromise of confidentiality, integrity, and availability (VC:H/VI:H/VA:H). Palo Alto Networks has released several patched versions across the 10.2, 11.1, 11.2, and 12.1 release trains to address this issue.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1 < 12.1.7, 11.2 < 11.2.4-h17, 11.2 < 11.2.7-h13, 11.2 < 11.2.10-h6, 11.2 < 11.2.12, 11.1 < 11.1.4-h33, 11.1 < 11.1.6-h32, 11.1 < 11.1.7-h6, 11.1 < 11.1.10-h25, 11.1 < 11.1.13-h5, 11.1 < 11.1.15, 10.2 < 10.2.7-h34, 10.2 < 10.2.10-h36, 10.2 < 10.2.13-h21, 10.2 < 10.2.16-h7, 10.2 < 10.2.18-h6
  • Siemens RUGGEDCOM APE1808 Virtual NGFW All versions with Authentication Profile with CAS enabled

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2026-05-28: patched: Advisory updated with fix versions

References

Related threats