CVE-2026-0298
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
Summary
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | 6.3.0 < 6.3.3-h14 | affected |
| Palo Alto Networks | GlobalProtect App | 6.2.0 < 6.2.8-h13 | affected |
| Palo Alto Networks | GlobalProtect App | 6.0.0 < 6.0.15 | affected |
| Palo Alto Networks | GlobalProtect App | All | unaffected |
Weaknesses
- CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')
Workarounds
Customers can mitigate the risk of this issue by taking either of the following actions:
Use Connect Before Logon (CBL (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method)) (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method) without SAML Authentication
Use Pre-logon with machine certificate (https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/remote-access-vpn-with-pre-logon) instead of Connect Before Logon (CBL).
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.