Improper Input Validation Vulnerability in Palo Alto Networks GlobalProtect App
CVE-2026-0298
Key Information:
- Vendor
Palo Alto Networks
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-0298?
An improper input validation flaw exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect app. This vulnerability could allow an attacker to perform a man-in-the-middle (MitM) attack, which may lead to the execution of arbitrary code with SYSTEM privileges on the affected Windows client devices. It is important to note that other operating systems, including Linux, macOS, iOS, Android, and Chrome OS, are not impacted by this issue. Timely remediation is critical to protecting systems that utilize this application.
Affected Version(s)
GlobalProtect App Windows 6.3.0 < 6.3.3-h14
GlobalProtect App Windows 6.2.0 < 6.2.8-h13
GlobalProtect App Windows 6.0.0 < 6.0.15
References
CVSS V4
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved