Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

PAN-OS GlobalProtect bypass: are your VPN trust controls enough?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: CVE-2026-0257 lets a remote attacker forge an authentication override cookie and gain unauthorized GlobalProtect VPN access, with exploitation requiring no user interaction and carrying a CVSS 7.8 score, according to CYCOGNITO. The issue shows how edge VPN trust assumptions and conditional configuration drift can turn an authentication control into an internal-network foothold.

NHIMG editorial — based on content published by CYCOGNITO: Sample of assets impacted by PAN-OS GlobalProtect Authentication Bypass vulnerability

By the numbers:

  • CVE-2026-0257 carries a CVSS base score of 7.8, indicating high severity for exposed GlobalProtect deployments.

Questions worth separating out

Q: What breaks when GlobalProtect override cookies are not properly validated?

A: The portal or gateway may accept a forged cookie as proof of authentication, which lets an attacker open a VPN session without valid credentials.

Q: Why do edge VPN appliances create outsized identity risk?

A: They sit at the boundary between public traffic and internal trust, so any authentication weakness can become direct access.

Q: How do security teams know whether a VPN bypass issue is actually dangerous in their environment?

A: They need to check three things together: internet exposure, affected software version, and the configuration flags that enable the vulnerable path.

Practitioner guidance

  • Inventory every internet-facing GlobalProtect instance Build a live list of portals and gateways, then confirm which are actually reachable from untrusted networks and whether they are running affected PAN-OS trains.
  • Disable authentication override where the feature is not required If the business does not need override cookies, remove that path entirely rather than leaving a dormant trust shortcut in production.
  • Separate cookie protection certificates from other uses Use a dedicated certificate for override cookie encryption and decryption, and verify that no other feature shares it.

What's in the full report

CYCOGNITO's full analysis covers the operational detail this post intentionally leaves for the source:

  • Affected PAN-OS and Prisma Access version ranges, including the exact fixed releases by train
  • The configuration conditions that make the issue exploitable, including override cookie settings and certificate reuse
  • Step-by-step remediation guidance for staging patches and validating re-authentication behaviour after upgrade
  • CyCognito's asset-exposure patterns across sectors, which help teams prioritise remediation in distributed estates

👉 Read CYCOGNITO's analysis of the PAN-OS GlobalProtect authentication bypass →

PAN-OS GlobalProtect bypass: are your VPN trust controls enough?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Cookie integrity is now an identity control, not a web detail. This vulnerability shows that session acceptance at the VPN edge can be just as important as primary authentication. When a forged artifact is enough to satisfy the portal, the control failure sits in the trust model, not the user credential. Practitioners should treat cookie validation as part of identity assurance, especially on exposed access gateways.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.

A question worth separating out:

Q: Who is accountable when a remote-access control allows unauthorised VPN sessions?

A: Accountability usually spans infrastructure, identity, and platform owners because the failure crosses certificates, session validation, and exposure management. NIST CSF and NIST SP 800-53 both expect clear access control ownership, and that ownership must extend to edge devices that mint trusted sessions.

👉 Read our full editorial: PAN-OS GlobalProtect cookie bypass exposes VPN trust assumptions



   
ReplyQuote
Share: