Improper Input Validation Vulnerability in Palo Alto Networks GlobalProtect App
CVE-2026-0298

5.2MEDIUM

Key Information:

Vendor
CVE Published:
13 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-0298?

An improper input validation flaw exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect app. This vulnerability could allow an attacker to perform a man-in-the-middle (MitM) attack, which may lead to the execution of arbitrary code with SYSTEM privileges on the affected Windows client devices. It is important to note that other operating systems, including Linux, macOS, iOS, Android, and Chrome OS, are not impacted by this issue. Timely remediation is critical to protecting systems that utilize this application.

Affected Version(s)

GlobalProtect App Windows 6.3.0 < 6.3.3-h14

GlobalProtect App Windows 6.2.0 < 6.2.8-h13

GlobalProtect App Windows 6.0.0 < 6.0.15

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

our internal security research teams
.