PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login
Vulnerability Description
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS® management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma® Access instances are proactively patched.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0126
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- D'Angelo Gonzalez of CrowdStrike
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →