CVE-2026-0307

Summary

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

This GlobalProtect app on iOS, Android and ChromeOS is not impacted.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h15affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h15affected
Palo Alto NetworksGlobalProtect App6.2.0 < 6.2.8-h14affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect AppAllaffected

Weaknesses

  • CWE-426: CWE-426 Untrusted Search Path

Workarounds

No known workarounds exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References