PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
Plan PatchCVSS 7.8CVE-2026-0283Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
An authentication bypass vulnerability in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN) functionality allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection without valid credentials. The vulnerability affects PAN-OS versions below 12.1.4-h8, 12.1.7-h2, 12.1.8 and Prisma Access versions below 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13. Panorama, Cloud NGFW, and Prisma Access are not impacted by this vulnerability.
What this means
What could happen
An attacker could bypass VPN authentication and establish an unauthorized site-to-site connection to your network, potentially gaining access to internal systems and process data. This could allow unauthorized monitoring or manipulation of control system traffic between facilities.
Who's at risk
Organizations using Palo Alto Networks PAN-OS devices to terminate site-to-site VPN connections between facilities should prioritize this fix. This is especially critical if you use PAN-OS firewalls to connect remote substations, water treatment plants, or other distributed control sites to your central network. Prisma Access customers providing remote VPN access to engineers and operations staff are also affected.
How it could be exploited
An attacker with network access to a PAN-OS device running LSVPN would send a specially crafted VPN connection request that bypasses the authentication checks. The attacker does not need valid credentials; the malformed request itself tricks the device into accepting the connection as legitimate, allowing the attacker to establish a site-to-site tunnel and route traffic into your network.
Prerequisites
- Network access to the PAN-OS LSVPN interface
- Target device running vulnerable PAN-OS or Prisma Access version
- No valid VPN credentials required
remotely exploitableno authentication requiredlow complexityauthentication bypass mechanism
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (7)
7 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.4-h2011.2.4-h20+
Prisma AccessBelow 11.2.7-h1811.2.7-h18+
Prisma AccessBelow 11.2.10-h1211.2.10-h12+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/5
Do now
0/2WORKAROUNDEnable Threat ID 510032 (requires Applications and Threats content version 9122-10145 or later) to detect and block exploitation attempts against this vulnerability
HARDENINGApply vulnerability protection security profile to GlobalProtect interfaces to ensure Threat ID 510032 protection is active on VPN access points
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.4-h8 or later (12.1.x branch), 12.1.7-h2 or later (12.1.x branch), or 12.1.8 or later (12.1.x branch)
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.4-h20 or later (11.2.x branch), 11.2.7-h18 or later (11.2.x branch), 11.2.10-h12 or later (11.2.x branch), or 11.2.13 or later (11.2.x branch)
Long-term hardening
0/1HARDENINGRestrict network access to LSVPN interfaces to only authorized remote site gateways; use firewall rules to block unexpected VPN connection attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/75935103-9343-4ed2-a9f5-42363bb10c1fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.