Status: NEW | Advisory ID: CVE-2026-0251
| CVE | CVE-2026-0251 |
| CVSS | CVSS 7.8 (High). |
| Affected products | Palo Alto Networks GlobalProtect |
| Classified as | CWE-426 (Untrusted Search Path) |
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-0251 |
| Vendor advisory | https://security.paloaltonetworks.com/CVE-2026-0251 |