CVE-2026-0298

Summary

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h14affected
Palo Alto NetworksGlobalProtect App6.2.0 < 6.2.8-h13affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect AppAllunaffected

Weaknesses

  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

Workarounds

Customers can mitigate the risk of this issue by taking either of the following actions:

  1. Use Connect Before Logon (CBL (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method)) (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method) without SAML Authentication

  2. Use Pre-logon with machine certificate (https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/remote-access-vpn-with-pre-logon) instead of Connect Before Logon (CBL).

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References