Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-2021
PAN-OS vulnerability analysis and mitigation

Overview

CVE-2020-2021 is a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS SAML authentication system. The vulnerability was disclosed on June 29, 2020, affecting PAN-OS versions 9.1 (earlier than 9.1.3), 9.0 (earlier than 9.0.9), 8.1 (earlier than 8.1.15), and all versions of PAN-OS 8.0. When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled, the system fails to properly verify SAML signatures, allowing unauthorized access to protected resources (Palo Alto).

Technical details

The vulnerability received a CVSS Base Score of 10.0 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The issue stems from improper verification of signatures in PAN-OS SAML authentication when the 'Validate Identity Provider Certificate' option is disabled. Resources that can be protected by SAML-based single sign-on authentication include GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series), Panorama web interfaces, and Prisma Access (Palo Alto).

Impact

The vulnerability allows an unauthenticated attacker with network access to the affected servers to gain access to protected resources if allowed by configured authentication and Security policies. In the case of PAN-OS and Panorama web interfaces, attackers can log in as administrators and perform administrative actions. For GlobalProtect Gateways, Portal, Clientless VPN, Captive Portal, and Prisma Access, attackers can gain unauthorized access to protected resources (Palo Alto).

Exploitability

The vulnerability requires network access to the vulnerable server for exploitation. The attacker must target systems where SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled. As of the initial disclosure, Palo Alto Networks was not aware of any malicious attempts to exploit this vulnerability in the wild (Palo Alto, TrustedSec).

Mitigation and workarounds

Organizations can mitigate this vulnerability by either upgrading to fixed versions (PAN-OS 8.1.15, PAN-OS 9.0.9, PAN-OS 9.1.3, or later versions) or by ensuring that the 'Validate Identity Provider Certificate' option is enabled in the SAML Identity Provider Server Profile. Using a different authentication method and disabling SAML authentication will completely mitigate the issue. For organizations using Prisma Access services, all services have been upgraded to resolve this issue and are no longer vulnerable (Palo Alto).

Community reactions

US Cyber Command urged timely patching based on the severity of this exposure. The vulnerability received significant attention from the cybersecurity community, with researchers noting that this configuration issue might be indicative of a systemic problem in SAML implementations. Many popular Identity Providers, including Microsoft's Azure Active Directory and Okta, had documentation suggesting the disabling of certificate validation, which contributed to the widespread potential impact (TrustedSec).

Additional resources


SourceThis report was generated using AI

Related PAN-OS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0301LOW1.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management