← All Advisories

CVE-2026-0251

Status: NEW  |  Advisory ID: CVE-2026-0251

Key Details

CVECVE-2026-0251
CVSSCVSS 7.8 (High).
Affected productsPalo Alto Networks GlobalProtect
Classified asCWE-426 (Untrusted Search Path)

What to Know

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0251
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0251