TL;DR: CVE-2026-0257 in Palo Alto GlobalProtect has been confirmed in the wild, according to Pomerium, with Rapid7 tracing successful attacks back to at least May 17 and CISA adding the flaw to its KEV catalog. One-time edge authentication turns a forged trust token into network reachability, so the real failure is a perimeter model that grants too much for too long.
At a glance
What this is: This is Pomerium’s analysis of the GlobalProtect bypass, arguing that a single trusted authentication event should not unlock network reachability.
Why it matters: It matters because VPN and edge-access designs still concentrate trust in one internet-facing decision point, which is exactly where identity attackers look for durable footholds.
Context
The core problem is a trust model, not just a bad bug. In a VPN architecture, one successful authentication event can confer broad network reachability, which means any flaw in how that trust is established or reused can become a full-access problem instead of a narrow application issue.
Pomerium’s article uses GlobalProtect CVE-2026-0257 to show how authentication override cookies can be forged when signing material is shared in a way the gateway accepts as genuine. The governance gap is that perimeter access is treated as a durable entitlement rather than a request-by-request decision.
The article also places this flaw in a wider pattern: when the network edge becomes the policy boundary, a single mistake can collapse the distinction between authenticated and anonymous traffic. That is not an isolated implementation bug, but a structural problem in how access is granted and trusted.
Key questions
Q: What breaks when a VPN gateway treats one login as durable trust?
A: The control breaks at the point where a successful edge authentication is allowed to imply broad internal reachability. After that, the gateway stops acting like a narrow access broker and starts acting like a network pass, so any bypass or forged token can expose more than the intended application. The failure is architectural, not just procedural.
Q: Why do forged VPN trust tokens create such a large risk?
A: Because they let an attacker inherit the trust of the gateway without proving identity in a live, request-specific way. Once the token is accepted, the attacker may receive a session that opens internal routing or network segments, which means the token is effectively a key to more than one resource.
Q: What are the signs that remote access controls are too broad for sensitive internal systems?
A: Remote access is too broad when users can reach more systems, files, or functions than their job requires, especially if clipboard, file transfer, or unrestricted shell access is left open by default. Another warning sign is access that stays active after role changes. If sessions are not restricted, recorded, or tied to specific targets, the control boundary is already too loose.
Q: How should teams respond when edge authentication can be bypassed?
A: Treat the bypass as evidence that network access and application access are too tightly coupled. Contain the exposure by narrowing what a session can reach, reviewing all routes opened by the gateway, and moving high-value services behind request-level policy instead of perimeter trust.
Technical breakdown
How forged authentication override cookies become a VPN session
GlobalProtect trusted authentication override cookies as proof that the gateway should create a session. In the scenario described by Pomerium, if the same certificate signs both HTTPS services and those cookies, an attacker can mint a cookie the firewall accepts as authentic. Once that trust check passes, the appliance issues a VPN session without requiring a password or MFA token. The key weakness is not the cookie format alone, but the assumption that a signed token at the edge is sufficient evidence for network entry.
Practical implication: review whether edge gateways accept bearer-style trust tokens that can be minted or replayed without fresh, request-scoped verification.
Why one-time edge authentication creates a large blast radius
A VPN concentrator makes one authorization decision and then extends IP-level reachability across the network segment behind it. That means the attacker does not need to keep proving identity while moving from one internal resource to another. Pomerium’s argument is that this creates a brittle trust boundary: the gateway becomes both the authentication point and the routing mechanism. When those functions are combined, a single bypass can collapse the boundary between externally authenticated and internally trusted traffic.
Practical implication: separate network connectivity from application authorization so one successful login cannot automatically imply broad internal reach.
How per-request access changes the control model
Pomerium describes a reverse proxy model where each request is evaluated against identity, device posture, and context before a specific upstream service is reached. That is materially different from a VPN model because the trust decision is repeated per request rather than assumed to hold for the whole session. The zero trust principle here is continuous verification, not one-time admission. A forged cookie may still open one pathway, but it does not inherently create an open network segment to pivot through.
Practical implication: move high-value applications behind per-request policy enforcement so compromised access is constrained to the specific resource being requested.
Threat narrative
Attacker objective: The attacker aims to obtain authenticated network access through the VPN gateway without possessing legitimate user credentials.
- Entry occurs when an attacker forges an authentication override cookie that the gateway accepts as genuine.
- Credential or trust-material abuse happens because the cookie is enough to trigger a VPN session without a password or MFA token.
- Impact follows when the gateway grants network reachability, turning a single bypass into an internal foothold that can support later movement.
Breaches seen in the wild
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
- CitrixBleed 2 2025: CitrixBleed 2 leaked NetScaler session tokens from memory, letting attackers hijack VPN sessions and skip MFA at 100+ organisations.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
One-time VPN trust is an assumption, not a control. The GlobalProtect case shows what happens when a perimeter device is allowed to turn one authentication event into enduring internal reachability. That model assumes the trust decision made at the edge remains valid after the session begins, which is exactly where it fails. For identity programmes, the lesson is that reachability must be evaluated as an access state, not a one-time proof.
Perimeter trust collapses when authentication and routing are fused. The gateway is not just checking identity, it is also becoming the path into the network. That creates a single compromise point that blends authentication, session creation, and transport into one failure domain. Practitioners should treat this as a governance problem as much as a technical one: the access decision and the network consequence are too tightly coupled.
Continuous verification is the more defensible trust boundary. Request-scoped policy does not eliminate risk, but it prevents one accepted token from becoming an open-ended internal foothold. That aligns more closely with Zero Trust Architecture than with legacy remote access patterns, and it changes the blast-radius calculation materially. The practitioner takeaway is to govern access at the application request, not the network perimeter.
Identity blast radius: the real unit of measurement is what a bypass can reach. A forged cookie matters because it does not merely create a session, it creates a corridor across internal resources. That corridor is what security teams need to design against when they choose remote access architecture. The implication is to measure access in terms of reachable services and request scope, not just successful logins.
VPNs remain high-value targets because they concentrate trust in a single internet-facing control plane. The article makes clear that this is not a case of poor patch discipline alone. It is a category problem: any design that equates entry with broad network trust will keep producing the same failure mode. Practitioners should re-evaluate whether their remote access model still assumes the network is the resource to protect.
What this signals
VPN trust is an access-design problem, not just an exploit pattern. A bypass only becomes strategically important when the underlying architecture turns one edge decision into broad internal reach. For IAM and network access teams, that means the next review should focus on what the gateway grants after authentication, not merely how the login is validated.
Per-request authorization is the sharper control boundary. When access is re-evaluated at the application request, a forged session token has far less room to become lateral movement. That does not remove the need to patch edge devices, but it does reduce the number of resources that a single trust failure can expose.
Zero Trust Architecture is most useful when it replaces network reachability with scoped access decisions. The practical question is whether your remote access design still treats the network as the prize. If it does, the same class of bypass will keep converting a session into a much larger security event.
For practitioners
- Audit trust-token handling at the edge Verify whether authentication override cookies, session tokens, or similar bearer artefacts can be minted, replayed, or reused without fresh policy evaluation.
- Separate connectivity from authorisation Reduce the number of systems where one login event creates broad IP-level reachability, and prefer controls that scope access to a specific application or request.
- Review certificate-signing overlap Check whether the same certificate or trust anchor signs both authentication material and unrelated web services, because that design can collapse token authenticity checks.
- Map internal exposure from a single VPN session Document which internal services become reachable after one successful edge authentication, then use that mapping to identify the largest blast-radius paths.
Key takeaways
- The article shows that the main problem is not only a vulnerability in GlobalProtect, but a VPN model that lets one trust decision open a broad internal path.
- Confirmed exploitation and CISA KEV placement underscore that edge-device trust failures become operationally urgent as soon as they are weaponised.
- The control that changes the outcome is not faster login verification, but narrower request-scoped access that prevents one session from inheriting the whole network.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The bypass works because the gateway accepts forged authentication material as genuine. |
| NHI-10 — Human Use of NHI | The cookie functions as a machine trust artefact that incorrectly grants human-style network access. | |
| Recommendation — Harden authentication flows so edge trust tokens cannot be accepted without strong, request-bound validation. Separate machine-held trust artefacts from user access decisions and scope them to the smallest possible resource. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture — Zero Trust Architecture | The article explicitly contrasts one-time perimeter trust with continuous request-based verification. |
| Recommendation — Apply zero trust principles so each request is re-authorised instead of inheriting broad session trust. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | This control maps to the need to narrow what authenticated access can reach after login. |
| Recommendation — Limit entitlements so a single authenticated session cannot open broad internal reachability. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The forged cookie provides the access needed to enter and then move through the environment. |
| Recommendation — Map gateway-bypass scenarios to credential access and lateral movement detections in your monitoring pipeline. | ||
Key terms
- Perimeter trust: Perimeter trust is the assumption that a successful login at the edge remains valid for broad internal access. In practice, it turns one authentication event into a durable entitlement. That model is fragile because any flaw in the gateway or session token can expose the full network, not just one application.
- Resource-Scoped Authorization: Resource-scoped authorization grants access relative to a specific object or subtree rather than across an entire tenant. In practice, it lets a user or agent act on one workspace, project, or branch while remaining blocked elsewhere, which is essential for fine-grained governance.
- Authentication override cookie: An authentication override cookie is a session artifact a gateway uses to recognise that a user has already authenticated. When poorly designed or improperly signed, it becomes a replayable proof of access. The risk is not the cookie itself, but the fact that the gateway may treat it as sufficient evidence for network reachability.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org