Palo Alto Networks Security Advisories / CVE-2026-0298

CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

Urgency MODERATE

047910
Severity 5.2 · MEDIUM
Exploit Maturity UNREPORTED
Response Effort MODERATE
Recovery USER
Value Density DIFFUSE
Attack Vector ADJACENT
Attack Complexity LOW
Attack Requirements PRESENT
Automatable NO
User Interaction NONE
Product Confidentiality HIGH
Product Integrity HIGH
Product Availability HIGH
Privileges Required NONE
Subsequent Confidentiality LOW
Subsequent Integrity NONE
Subsequent Availability NONE

Description

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Product Status

VersionsAffectedUnaffected
GlobalProtect AppNone on Linux
None on macOS
None on Android
None on Chrome OS
None on iOS
All on Linux
All on macOS
All on Android
All on Chrome OS
All on iOS
GlobalProtect App 6.3< 6.3.3-h14 (6.3.3-1121) on Windows
>= 6.3.3-h14 (6.3.3-1121) on Windows
GlobalProtect App 6.2< 6.2.8-h13 (6.2.8-1045) on Windows
>= 6.2.8-h13 (6.2.8-1045) on Windows
GlobalProtect App 6.0< 6.0.15 on Windows (ETA: 08/31)
>= 6.0.15 on Windows (ETA: 08/31)

Required Configuration for Exposure

This issue is applicable only to devices configured to use SAML authentication in the GlobalProtect Connect Before Logon feature.

Severity: MEDIUM, Suggested Urgency: MODERATE

CVSS-BT: 5.2 / CVSS-B: 7.7 (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Weakness Type and Impact

CWE-94 Improper Control of Generation of Code ('Code Injection')

CAPEC-242 Code Injection

Solution

Version
Minor Version
Suggested Solution
GlobalProtect App 6.3 on Windows
6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later.
GlobalProtect App 6.2 on Windows
6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later.
GlobalProtect App 6.0 on Windows
6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.
GlobalProtect App All on macOS
No action needed.
GlobalProtect App All on Linux
No action needed.
GlobalProtect App All on iOS
No action needed.
GlobalProtect App All on Android
No action needed.
GlobalProtect App All on Chrome OS
No action needed.

Workarounds and Mitigations

Customers can mitigate the risk of this issue by taking either of the following actions:

  1. Use Connect Before Logon (CBL) without SAML Authentication

  2. Use Pre-logon with machine certificate instead of Connect Before Logon (CBL).

Acknowledgments

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

CPEs

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:Windows:*:*

cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:Windows:*:*

CPE Applicability

Timeline

Initial Publication
© 2026 Palo Alto Networks, Inc. All rights reserved.