PT-2026-38422 · Undefined · Undefined
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Forms WordPress plugin versions prior to 6.2.1
PAN-OS versions prior to 10.2.9-h1
PAN-OS versions prior to 11.0.4-h2
PAN-OS versions prior to 11.1.2-h3
Description
Fluent Forms contains an issue where ownership is not properly verified before processing subscription cancellation requests, allowing authenticated users with low-privilege accounts to cancel subscriptions belonging to other users.
PAN-OS is affected by an unauthenticated remote root code execution flaw in the
mgmtsrvr and authd processes. The issue occurs during the parsing of Security Assertion Markup Language (SAML) authentication requests, where a flaw in the sanitization routine allows shell metacharacters to be passed to a backend system command used for certificate verification. An attacker can embed a command string within the Issuer tag of a specially crafted XML request sent to the GlobalProtect portal or the management web interface. This results in the execution of the malicious string via a system() call with root privileges, potentially allowing the installation of a kernel-level rootkit and the decryption of SSL/TLS traffic.Recommendations
Update Fluent Forms to version 6.2.1 or later.
Update PAN-OS 10.2 to version 10.2.9-h1 or later.
Update PAN-OS 11.0 to version 11.0.4-h2 or later.
Update PAN-OS 11.1 to version 11.1.2-h3 or later.
Disable web management to ensure the Management Interface is not accessible from the public internet.
Switch from SAML to alternative authentication methods, such as LDAP or local accounts with MFA.
Restrict access to the GlobalProtect Portal/Gateway to known-good IP ranges only.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined