Junglewise Threat Intelligence

CVE-2026-0283: Palo Alto Networks PAN-OS auth bypass in Large Scale VPN

CVE-2026-0283 · Severity: info · CVSS 4.5 · Published 2026-07-09

Vendors: Palo Alto Networks.

Executive brief

A security flaw in Palo Alto Networks PAN-OS software could allow an unauthorized person to connect to a company's private network. This issue affects the Large Scale VPN (LSVPN) feature used to connect multiple branch offices or sites. If exploited, an attacker could establish an unauthorized connection to the network, potentially bypassing security controls intended to restrict access.

Technical details

An authentication bypass vulnerability (CWE-306) exists in the Large Scale VPN (LSVPN) component of Palo Alto Networks PAN-OS. The flaw allows an unauthenticated attacker with network access to the GlobalProtect portal to bypass security restrictions and establish unauthorized site-to-site VPN connections. This issue specifically impacts firewalls configured with LSVPN satellites. Attackers can exploit this without user interaction or prior privileges. Palo Alto Networks has released patches for affected versions across the 10.2, 11.1, 11.2, and 12.1 release trains. Threat Prevention signatures (ID 510032) provide limited mitigation.

Affected products

  • Palo_Alto_Networks PAN-OS 12.1 < 12.1.4-h8, 12.1.5 < 12.1.7-h2, 11.2 < 11.2.4-h20, 11.2.5 < 11.2.7-h18, 11.2.8 < 11.2.10-h12, 11.2.11 < 11.2.13, 11.1 < 11.1.16, 10.2 < 10.2.18-h8

Timeline

  • 2026-07-08: disclosed: Discovered internally by Palo Alto Networks
  • 2026-07-08: advisory
  • 2026-07-09: patched: NVD publication date

References