Palo Alto GlobalProtect local privilege escalation (CVE-2026-0251)
Palo Alto Networks advisory CVE-2026-0251 (published 13 May 2026, updated 27 August 2026 after a public PoC): multiple local privilege-escalation bugs in the GlobalProtect app (CWE-426 untrusted search path) let a local user reach NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, then run commands with administrative privileges. iOS, Android, Chrome OS and the GlobalProtect UWP app are not affected. No special configuration is required. Vendor CVSS-BT is 7.1 (CVSS 4.0); the same advisory lists CVSS-B 8.5. Exploit maturity is POC. Palo Alto Networks says it is not aware of malicious exploitation. Distinct from CVE-2026-0299 already on this desk.
- Product
- Palo Alto Networks GlobalProtect app
- Versions
- 6.3, 6.2 and 6.0 on Windows, macOS and Linux as listed in the advisory (not iOS/Android/Chrome OS/UWP)
- CVSS
- (CVSS 4.0 BT, Palo Alto Networks); 8.5 CVSS-B
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- 6.3.3-h11 (Windows/macOS) or 6.3.3-h2 (Linux); 6.2.8-h10 (Windows/macOS); 6.0.13 (Windows/macOS) or 6.0.11 (Linux). Linux 6.2: upgrade to 6.3.3-h2.
Primary: Palo Alto Networks PSIRT (CVE-2026-0251) · Vendor: Palo Alto Networks security advisories · CVE: CVE-2026-0251, CVE-2026-0299
