← All Advisories

CVE-2026-0299

Status: UPDATED  |  Advisory ID: CVE-2026-0299

Key Details

CVECVE-2026-0299
CVSSCVSS 7.8 (High): attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected productsPalo Alto Networks GlobalProtect
Exploitation statusPalo Alto Networks is not aware of any malicious exploitation of this issue.

What to Know

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

What to Do

GlobalProtect App: fixed releases vary by platform and prior version (6.3.3-h15 on Linux, 6.3.3-h14 on macOS/Windows, 6.0.15 for 6.0.x) -- see the advisory's own version table for the exact upgrade path.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0299
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0299