← Vulnerability feed

Vulnerability record · CVE-2020-2021 · published 29 June 2020

CVE-2020-2021: PAN-OS SAML signature verification bypass allows authentication bypass

Paloaltonetworks · Pan Os

PAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchecked. An unauthenticated network attacker can then forge SAML assertions and reach resources protected by SAML SSO, including GlobalProtect portals/gateways, Clientless VPN, Captive Portal, Prisma Access, and PAN-OS/Panorama web interfaces.

10.0 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 Known ransomware use EPSS 4.4% · top 9.1% CWE-347 · Improper verification of cryptographic signature
10.0CVSS 3.1 base score, v2 9.3
4.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. This issue cannot be exploited if SAML is not used for authentication. This issue cannot be exploited if the 'Validate Identity Provider Certificate' option is enabled (checked) in the SAML Identity Provider Server Profile. Resources that can be protected by SAML-based single sign-on (SSO) authentication are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces, Prisma Access In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies. There is no impact on the integrity and availability of the gateway, portal or VPN server. An attacker cannot inspect or tamper with sessions of regular users. In the worst case, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). In the case of PAN-OS and Panorama web interfaces, this issue allows an unauthenticated attacker with network access to the PAN-OS or Panorama web interfaces to log in as an administrator and perform administrative actions. In the worst-case scenario, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). If the web interfaces are only accessible to a restricted management network, then the issue is lowered to a CVSS Base Score of 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Palo Alto Networks is not aware of any malicious attempts to exploit this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 10.0 authentication bypass with no preconditions beyond a common misconfiguration, listed in CISA KEV with known ransomware use.

What it is

PAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchecked. An unauthenticated network attacker can then forge SAML assertions and reach resources protected by SAML SSO, including GlobalProtect portals/gateways, Clientless VPN, Captive Portal, Prisma Access, and PAN-OS/Panorama web interfaces.

Impact

An attacker gains access to protected resources without valid credentials; against PAN-OS or Panorama web interfaces this means logging in as an administrator and performing administrative actions. Integrity and availability of the gateway, portal, or VPN server itself are not affected, and regular user sessions cannot be inspected or tampered with.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N); the only precondition is that SAML is used for authentication and the 'Validate Identity Provider Certificate' option is disabled. If the web interfaces sit on a restricted management network, the vector becomes adjacent (AV:A) and the score drops to 9.6.

Exploitation

Listed in CISA KEV (added 2022-03-25, due 2022-04-15) with known ransomware campaign use, so exploitation has occurred in the wild. EPSS 30-day probability is 0.04362 (90.8th percentile), and the vendor stated at publication it was not aware of malicious attempts.

What to do

  • Upgrade to PAN-OS 9.1.3, 9.0.9, or 8.1.15 or later; PAN-OS 8.0 is EOL and must be replaced.
  • Enable the 'Validate Identity Provider Certificate' option in the SAML Identity Provider Server Profile.
  • If SAML is not required, disable SAML authentication.
  • Restrict network access to PAN-OS and Panorama management web interfaces to a trusted management network.
  • Review SAML IdP configurations and certificates for unauthorized changes.

Detection

  • Audit PAN-OS and Panorama configurations for SAML authentication enabled with 'Validate Identity Provider Certificate' unchecked.
  • Monitor authentication logs for successful SAML logins from unexpected source IPs or without a corresponding IdP-side authentication event.
  • Alert on administrative logins to PAN-OS or Panorama web interfaces from outside the management network.
  • Hunt for GlobalProtect, Clientless VPN, or Captive Portal sessions that begin without prior credential or IdP authentication.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-2021 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2021 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2020-2021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.