CVE-2025-0126 Details
Description
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS® management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma® Access instances are proactively patched.
A session fixation vulnerability has been identified in the GlobalProtect login when SAML authentication is used. This vulnerability allows an attacker to impersonate a legitimate user and perform actions on their behalf. The exploitation requires the user to click on a malicious link from the attacker. This issue does not affect the SAML login for the PAN-OS management interface, Cloud NGFW, or Prisma Access instances, which have been proactively patched.
Users can upgrade to a fixed version of PAN-OS. For specific upgrade instructions, refer to the Palo Alto Networks documentation. As a workaround, consider using a different authentication method for the GlobalProtect portal, such as Client Certificate Authentication, RADIUS, TACACS+, LDAP, or Kerberos.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 11, 2025CISA-ADP
Assessed Apr 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-0126 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-384 | Session Fixation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Palo Alto Networks PAN-OS | <= 11.2.2 (semver) <= 11.1.4 (semver) <= 11.0.5 (semver) <= 10.2.10 (semver) <= 10.2.9 (semver) <= 10.2.4 (semver) <= 10.1.14 (semver) |
CPE
Remediation
| |
| Palo Alto Networks GlobalProtect | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 11, 2025 | New CVE Received | [email protected] |
Volerion