CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Description
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| GlobalProtect App | None on Linux None on macOS None on Android None on Chrome OS None on iOS | All on Linux All on macOS All on Android All on Chrome OS All on iOS |
| GlobalProtect App 6.3 | < 6.3.3-h14 (6.3.3-1121) on Windows | >= 6.3.3-h14 (6.3.3-1121) on Windows |
| GlobalProtect App 6.2 | < 6.2.8-h13 (6.2.8-1045) on Windows | >= 6.2.8-h13 (6.2.8-1045) on Windows |
| GlobalProtect App 6.0 | < 6.0.15 on Windows (ETA: 08/31) | >= 6.0.15 on Windows (ETA: 08/31) |
Required Configuration for Exposure
This issue is applicable only to devices configured to use SAML authentication in the GlobalProtect Connect Before Logon feature.
Severity: MEDIUM, Suggested Urgency: MODERATE
CVSS-BT: 5.2 / CVSS-B: 7.7 (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Weakness Type and Impact
CWE-94 Improper Control of Generation of Code ('Code Injection')
Solution
| Version | Minor Version | Suggested Solution |
|---|---|---|
| GlobalProtect App 6.3 on Windows |
6.3.0 through 6.3.3-h13 | Upgrade to 6.3.3-h14 (6.3.3-1121) or later. |
| GlobalProtect App 6.2 on Windows |
6.2.0 through 6.2.8-h12 | Upgrade to 6.2.8-h13 (6.2.8-1045) or later. |
| GlobalProtect App 6.0 on Windows |
6.0.0 through 6.0.14 | Upgrade to 6.0.15 or later. |
| GlobalProtect App All on macOS | No action needed. | |
| GlobalProtect App All on Linux | No action needed. | |
| GlobalProtect App All on iOS | No action needed. | |
| GlobalProtect App All on Android | No action needed. | |
| GlobalProtect App All on Chrome OS | No action needed. |
Workarounds and Mitigations
Customers can mitigate the risk of this issue by taking either of the following actions:
Use Connect Before Logon (CBL) without SAML Authentication
Use Pre-logon with machine certificate instead of Connect Before Logon (CBL).
Acknowledgments
CPEs
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Windows:*:*
CPE Applicability
- cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Windows:*:* is vulnerable from (including)6.3.3 and up to (excluding)6.3.3-h14
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Windows:*:* is vulnerable from (including)6.2.8 and up to (excluding)6.2.8-h13
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Windows:*:* is vulnerable from (including)6.0.0 and up to (excluding)6.0.15