Palo Alto Networks says CVE-2026-0257 can allow unauthorized VPN connections when specific GlobalProtect authentication override cookie settings are e

What CVE-2026-0257 Puts at Risk

Palo Alto Networks has described CVE-2026-0257 as a condition that can allow unauthorized VPN connections when specific GlobalProtect authentication override cookie settings are in use. VPN gateways sit at the edge of the network. They decide who may establish a tunnel and what internal resources that tunnel can reach. When the decision path depends on a cookie rather than a full, live authentication exchange, a weakness in how that cookie is issued, accepted, or scoped can short-circuit controls teams assume are always enforced.

Authentication override cookies exist to reduce friction: they let a client resume or bypass parts of the login flow under conditions the administrator has chosen. That convenience is useful for users who reconnect often, but it expands the attack surface. The gateway is no longer checking only credentials and policy at the moment of connect; it is also trusting prior state stored in a cookie. CVE-2026-0257 keeps pressure on those gateways because any misconfigured or overly permissive override path can turn a remote login endpoint into an unauthorized entry point.

Why Override Cookies Need Tight Configuration

Override cookies are not inherently unsafe. They become a problem when acceptance rules are broad, when lifetime is long, when binding to user, device, or session context is weak, or when the cookie is honored even after credentials, group membership, or posture checks should have been revalidated. Operators often enable override features to cut help-desk load or improve roaming experience, then leave defaults in place longer than intended. The result is a policy that looks strict in the authentication profile but soft in the cookie path.

Unauthorized VPN access does not always look like a noisy brute-force event. A successful cookie-based bypass can present as a normal client session: expected protocols, familiar user agents, and traffic that blends with legitimate remote work. That makes detection harder and increases the value of prevention at the gateway—reviewing whether override is required at all, and if it is, how narrowly it is constrained.

Practical Steps for Operators Under Pressure

Treat CVE-2026-0257 as a prompt to re-examine GlobalProtect authentication design, not only as a one-time patch ticket. Start by inventorying which portals and gateways use authentication override cookies, who enabled them, and what problem they were solving. Disable override where the operational benefit is unclear. Where override must stay, restrict it to the smallest set of users, portals, and client conditions that still meet the business need, and ensure cookie lifetime and re-authentication rules match your risk tolerance for remote access.

  • Confirm vendor guidance for CVE-2026-0257 and apply the recommended fixes or configuration changes on every exposed GlobalProtect gateway.
  • Review authentication profiles for override cookie settings that accept sessions without a full challenge when one should still be required.
  • Align cookie behavior with MFA, certificate, and device checks so a cookie cannot become a standalone trust root.
  • Watch for unexpected successful VPN sessions, especially from unfamiliar clients, unusual times, or accounts that should not use override flows.
  • Document approved override use cases so future changes do not reintroduce broad cookie acceptance by accident.

Keeping Gateways Hardened After the Fix

Patching and reconfiguration close the known issue, but the underlying tradeoff remains: remote access systems will keep offering shortcuts that trade repeated authentication for smoother reconnects. Teams that treat GlobalProtect as a long-lived edge service—with change control on auth settings, periodic config reviews, and clear owners for portal and gateway policy—are less likely to rediscover the same class of problem the next time a related issue appears.

CVE-2026-0257 is a reminder that “VPN up” is not the same as “access authorized under current policy.” Unauthorized connections through a trusted gateway are high impact because the tunnel itself is often allowed deep into internal networks. Keep override cookies as an explicit, justified exception, not a silent default, and revalidate that stance whenever authentication or client software changes. That discipline is what reduces ongoing pressure on the gateway after this specific CVE is addressed.

Automate Your Content with AI Video Generator

Try it Free →