CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities
Description
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| GlobalProtect App | None on iOS None on Android None on Chrome OS | All on iOS All on Android All on Chrome OS |
| GlobalProtect App 6.3 | < 6.3.3-h15 on Linux < 6.3.3-h14 (6.3.3-1121) on macOS < 6.3.3-h14 (6.3.3-1121) on Windows | >= 6.3.3-h15 on Linux (ETA: 08/28) >= 6.3.3-h14 (6.3.3-1121) on macOS >= 6.3.3-h14 (6.3.3-1121) on Windows |
| GlobalProtect App 6.2 | All on Linux < 6.2.8-h13 (6.2.8-1045) on macOS < 6.2.8-h13 (6.2.8-1045) on Windows | None on Linux >= 6.2.8-h13 (6.2.8-1045) on macOS >= 6.2.8-h13 (6.2.8-1045) on Windows |
| GlobalProtect App 6.0 | < 6.0.15 on Linux < 6.0.15 on macOS < 6.0.15 on Windows | >= 6.0.15 on Linux (ETA: 08/31) >= 6.0.15 on macOS (ETA: 08/31) >= 6.0.15 on Windows (ETA: 08/31) |
Required Configuration for Exposure
No special configuration is required to be affected by this issue.
Severity: MEDIUM, Suggested Urgency: MODERATE
CVSS-BT: 5.9 / CVSS-B: 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Weakness Type and Impact
CAPEC-233 Privilege Escalation
Solution
| Version | Minor Version | Suggested Solution |
|---|---|---|
| GlobalProtect App 6.3/6.2 on Linux |
6.2.0 through 6.3.3-h14 |
Upgrade to 6.3.3-h15 or later. |
| GlobalProtect App 6.0 on Linux | 6.0.0 through 6.0.14 | Upgrade to 6.0.15 or later. |
| GlobalProtect App 6.3 on macOS |
6.3.0 through 6.3.3-h13 | Upgrade to 6.3.3-h14 (6.3.3-1121) or later. |
| GlobalProtect App 6.3 on Windows |
6.3.0 through 6.3.3-h13 | Upgrade to 6.3.3-h14 (6.3.3-1121) or later. |
| GlobalProtect App 6.2 on macOS |
6.2.0 through 6.2.8-h12 | Upgrade to 6.2.8-h13 (6.2.8-1045) or later. |
| GlobalProtect App 6.2 on Windows |
6.2.0 through 6.2.8-h12 | Upgrade to 6.2.8-h13 (6.2.8-1045) or later. |
| GlobalProtect App 6.0 on macOS |
6.0.0 through 6.0.14 | Upgrade to 6.0.15 or later. |
| GlobalProtect App 6.0 on Windows |
6.0.0 through 6.0.14 | Upgrade to 6.0.15 or later. |
| GlobalProtect App on iOS | No action needed. | |
| GlobalProtect App on Android | No action needed. | |
| GlobalProtect App on Chrome OS | No action needed. |
Workarounds and Mitigations
No known workarounds exist for this issue.
Acknowledgments
CPEs
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.9:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c982:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c948:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c910:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c471:*:*:*:*:Linux:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c431:*:*:*:*:Linux:*:*
CPE Applicability
- cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Linux:*:* is vulnerable from (including)6.3.3 and up to (excluding)6.3.3-h15
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Linux:*:* is vulnerable from (including)6.2.0
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Linux:*:* is vulnerable from (including)6.0.0 and up to (excluding)6.0.15
- or
- cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:macOS:*:* is vulnerable from (including)6.3.3 and up to (excluding)6.3.3-h14
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Windows:*:* is vulnerable from (including)6.3.3 and up to (excluding)6.3.3-h14
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:macOS:*:* is vulnerable from (including)6.2.8 and up to (excluding)6.2.8-h13
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Windows:*:* is vulnerable from (including)6.2.8 and up to (excluding)6.2.8-h13
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:macOS:*:* is vulnerable from (including)6.0.0 and up to (excluding)6.0.15
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:Windows:*:* is vulnerable from (including)6.0.0 and up to (excluding)6.0.15