Local Privilege Escalation in Palo Alto Networks GlobalProtect App
CVE-2026-0299
Key Information:
- Vendor
Palo Alto Networks
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-0299?
The GlobalProtect app from Palo Alto Networks is susceptible to local privilege escalation vulnerabilities, allowing a local user to gain elevated privileges, effectively giving them the ability to execute commands with administrative rights on affected systems. This impacts Windows systems by allowing escalation to NT AUTHORITY\SYSTEM and enables similar escalations on macOS and Linux platforms, while the GlobalProtect app on iOS, Android, and Chrome OS remains unaffected. Users of the impacted versions should implement maintenance strategies to mitigate risks associated with this vulnerability.
Affected Version(s)
GlobalProtect App Linux 6.3.0 < 6.3.3-h15
GlobalProtect App Linux 6.2.0
GlobalProtect App Linux 6.0.0 < 6.0.15
References
CVSS V4
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved