Vulnerability
Published 2026-09-09
Verified 2026-09-19

Palo Alto GlobalProtect App LPE CVE-2026-0307 (CVSS-BT 5.9 / CVSS-B 8.5); PSIRT updated 16 Sep

Palo Alto Networks PSIRT CVE-2026-0307 (published 9 September 2026, updated 16 September 2026): multiple local privilege-escalation vulnerabilities in the GlobalProtect app (CWE-426 untrusted search path) let a local low-privileged user reach NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, then run arbitrary commands with administrative privileges. iOS, Android and ChromeOS are not impacted. No special configuration required. Vendor CVSS-BT 5.9 MEDIUM (CVSS 4.0); CVSS-B 8.5; exploit maturity UNREPORTED; urgency MODERATE. Palo Alto Networks says it is not aware of malicious exploitation. Fixes: GlobalProtect 6.3.3-h15+ (Windows/macOS/Linux; Linux ETA ~17 Sep, Windows/macOS ETA ~28 Sep on the advisory), 6.2.8-h14+ (Windows/macOS), 6.0.15+ (Linux/macOS; Windows ETA ~29 Oct). NGFW customers must also upgrade PAN-OS and Prisma Access tenants to builds listed in the Solution table (e.g. PAN-OS 12.2.3, 12.1.10 / 12.1.7-h5 / 12.1.4-h10, and listed 11.2/11.1/10.2 hotfixes). Prisma Access scheduled maintenance upgrades; on-demand via Support. Distinct from desk cards cve-2026-0299 and cve-2026-0251. Primary: Palo Alto Networks PSIRT.

Product
Palo Alto Networks GlobalProtect app (Windows/macOS/Linux); related PAN-OS / Prisma Access upgrades required for NGFW/PA tenants
Versions
Affected: GP 6.3 < 6.3.3-h15; 6.2 < 6.2.8-h14 (Win/macOS); 6.0 < 6.0.15 (Linux/macOS/Windows). Not iOS/Android/ChromeOS. See advisory for PAN-OS fixed builds.
CVSS
(CVSS 4.0 BT, Palo Alto Networks); 8.5 CVSS-B
Exploited in Australia?
unknown
Patch to
Upgrade GlobalProtect to 6.3.3-h15+, 6.2.8-h14+, or 6.0.15+ per OS; upgrade PAN-OS/Prisma Access to Solution-table builds; Prisma Access via scheduled or on-demand upgrade

Primary: Palo Alto Networks PSIRT — CVE-2026-0307 (updated 16 Sep 2026) · Vendor: Palo Alto Networks (vendor) · CVE: CVE-2026-0307, CVE-2026-0299, CVE-2026-0251 · Palo Alto Networks security advisories hub

vulnerabilities network