CVE-2026-0295
published 2026-08-13CVE-2026-0295: A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges…
PriorityP419medium4.1CVSS 4.0
AVLACLATPPRLUINVCHVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
EPSS
0.08%
0.3th percentile
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | globalprotect_app | >= 6.0.0 < 6.0.15 | 6.0.15 |
| palo_alto_networks | globalprotect_app | >= 6.2.0 < 6.2.8-h13 (6.2.8-1045) | 6.2.8-h13 (6.2.8-1045) |
| palo_alto_networks | globalprotect_app | >= 6.3.0 < 6.3.3-h14 (6.3.3-1121) | 6.3.3-h14 (6.3.3-1121) |
| paloalto | globalprotect_app | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
vendor_paloalto·CVSS 7.2
CVE-2026-0295 CWE-362 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Affected products: GlobalProtect App
Solution: VERSION MINOR VERSION SUGGESTED SOLUTION
GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later.
GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later.
GlobalProtect App 6.0 on macOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.
GlobalProtect App on Linux No action needed.
GlobalProtect App on Windows No action needed.
GlobalProt
GHSA
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
ghsa_unreviewed·2026-08-13
CVE-2026-0295 [MEDIUM] CWE-362 A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published