Vulnerability
Published 2026-08-12
Verified 2026-09-19

Palo Alto GlobalProtect local privilege escalation (CVE-2026-0299)

Palo Alto Networks 12 August 2026 advisory: local privilege-escalation bugs in the GlobalProtect app let a local user reach NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, then run commands with administrative privileges. iOS, Android and Chrome OS are not affected. Vendor CVSS-BT is 5.9 (CVSS 4.0); the same advisory lists CVSS-B 8.5 without the exploit-maturity modifier. Palo Alto Networks says it is not aware of malicious exploitation. Same-day GlobalProtect app advisories cover CVE-2026-0295 (macOS race-condition LPE, CVSS-BT 4.1), CVE-2026-0296 (certificate-validation bypass of app traffic, not the VPN tunnel, CVSS-BT 4.5), CVE-2026-0297 (UDP tunnel handshake buffer overflow, CVSS-BT 5.2) and CVE-2026-0298 (Windows PLAP MitM code execution, CVSS-BT 5.2 / CVSS-B 7.7). Those sibling advisories show Updated 2026-09-12 on the PSIRT hub; Palo Alto Networks still says it is not aware of malicious exploitation. PAN-OS URL Filtering information disclosure CVE-2026-0301 (CVSS 1.7) was also published 12 August. Prisma Access Agent LPE CVE-2026-0294 (CVSS-BT 6.0; patch 26.3+) remains a related same-day PSIRT item.

Product
Palo Alto Networks GlobalProtect app
Versions
6.3, 6.2 and 6.0 on Windows, macOS and Linux as listed in the advisory (not iOS/Android/Chrome OS)
CVSS
(CVSS 4.0 BT, Palo Alto Networks); 8.5 CVSS-B
Exploited in Australia?
unknown
Patch to
6.3.3-h14 (Windows/macOS) or 6.3.3-h15 (Linux); 6.2.8-h13 (Windows/macOS); 6.0.15 (Linux/macOS/Windows; PSIRT hub ETA ~29 Oct 2026 as of Updated 2026-09-12)

Primary: Palo Alto Networks PSIRT (CVE-2026-0299) · Vendor: Palo Alto Networks security advisories · CVE: CVE-2026-0299, CVE-2026-0295, CVE-2026-0296, CVE-2026-0297, CVE-2026-0298, CVE-2026-0301, CVE-2026-0294

vulnerabilities network