CVE-2026-0299
published 2026-08-13CVE-2026-0299: Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM…
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | globalprotect_app | — | — |
| palo_alto_networks | globalprotect_app | >= 6.0.0 < 6.0.15 | 6.0.15 |
| palo_alto_networks | globalprotect_app | >= 6.2.0 < 6.2.8-h13 | 6.2.8-h13 |
| palo_alto_networks | globalprotect_app | >= 6.3.0 < 6.3.3-h15 | 6.3.3-h15 |
| palo_alto_networks | globalprotect_app | >= 6.3.0 < 6.3.3-h14 | 6.3.3-h14 |
| paloalto | globalprotect_app | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
GlobalProtect App: Local Privilege Escalation Vulnerabilities
vendor_paloalto·CVSS 8.5
CVE-2026-0299 CWE-426 GlobalProtect App: Local Privilege Escalation Vulnerabilities
GlobalProtect App: Local Privilege Escalation Vulnerabilities
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected products: GlobalProtect App
Solution: VERSION MINOR VERSION SUGGESTED SOLUTION
GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later.
GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.
GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later.
Glob
GHSA
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux.
ghsa_unreviewed·2026-08-13
CVE-2026-0299 [MEDIUM] CWE-426 Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux.
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published