CVE-2026-0298
published 2026-08-13CVE-2026-0298: An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on…
PriorityP428medium5.2CVSS 4.0
AVAACLATPPRNUINVCHVIHVAHSCLSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
EPSS
0.19%
8.4th percentile
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | globalprotect_app | >= 6.0.0 < 6.0.15 | 6.0.15 |
| palo_alto_networks | globalprotect_app | >= 6.2.0 < 6.2.8-h13 | 6.2.8-h13 |
| palo_alto_networks | globalprotect_app | >= 6.3.0 < 6.3.3-h14 | 6.3.3-h14 |
| paloalto | globalprotect_app | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
vendor_paloalto·CVSS 7.7
CVE-2026-0298 CWE-94 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Affected products: GlobalProtect App
Solution: VERSION MINOR VERSION SUGGESTED SOLUTION
GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later.
GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later.
GlobalProtect App 6.0 on Windows 6.
GHSA
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-m
ghsa_unreviewed·2026-08-13
CVE-2026-0298 [MEDIUM] CWE-94 An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-m
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published