CVE-2026-0299

Summary

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h15affected
Palo Alto NetworksGlobalProtect App6.2.0affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h14affected
Palo Alto NetworksGlobalProtect App6.2.0 < 6.2.8-h13affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect AppAllunaffected

Weaknesses

  • CWE-426: CWE-426 Untrusted Search Path

Workarounds

No known workarounds exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References