Security Advisory Desk
highQCS priority 94/100Palo Alto Networks

CVE-2026-0251 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: HIGH)

A security issue in the Palo Alto Networks GlobalProtect app lets a local user increase their access rights on a computer. This means someone with basic user access could gain full system control if they are on the affected Windows, macOS, or Linux device. The issue does not affect Android, iOS, Chrome OS, or UWP versions of the app. Users should upgrade their GlobalProtect app to the fixed versions to stop this vulnerability from being exploited.

Published 27/8/2026, 1:00:00 amVerified 1/9/2026, 12:07:39 amRevision 1
Palo Alto Networks high network security advisory visual

In plain language

What this advisory means

A security issue in the Palo Alto Networks GlobalProtect app lets a local user increase their access rights on a computer. This means someone with basic user access could gain full system control if they are on the affected Windows, macOS, or Linux device. The issue does not affect Android, iOS, Chrome OS, or UWP versions of the app. Users should upgrade their GlobalProtect app to the fixed versions to stop this vulnerability from being exploited.

Technical explanation

How the issue affects the environment

The vulnerability CVE-2026-0251 affects the GlobalProtect app on Windows, macOS, and Linux platforms. It involves multiple local privilege escalation flaws that allow a user with low privileges to escalate to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux. The exploitation vector is local with low complexity and no user interaction needed, allowing arbitrary command execution with administrator rights. The flaw stems from an untrusted search path weakness (CWE-426), potentially allowing execution of unauthorized code with elevated privileges. Palo Alto Networks has issued upgrades that address these issues in versions 6.0.13+, 6.2.8-h10+, and 6.3.3-h11+ depending on platform and series.

Operational impact

Why teams should care

If exploited, a local attacker could fully compromise affected systems, breaching confidentiality, integrity, and availability by executing commands as system or root user. This can lead to unauthorized data access, system changes, or denial of service, impacting business operations and security compliance. Since the vulnerability requires local access, insider threats or compromised endpoints are primary concerns. No known exploitation in the wild has been reported, but the risk remains significant without upgrading.

Immediate action

Upgrade your GlobalProtect app to the versions specified as fixed: 6.0.13 or newer on Windows and macOS, 6.0.11 or newer on Linux, 6.2.8-h10 or newer on Windows and macOS, 6.3.3-h11 or newer on Windows and macOS, and 6.3.3-h2 or newer on Linux to address these vulnerabilities.

Affected and fixed releases

Affected versionsGlobalProtect 6.0.0 through 6.0.12 on Windows and macOS; through 6.0.10 on Linux, GlobalProtect 6.2.0 through 6.2.8-h9 on Windows and macOS; through 6.2.9 on Linux, GlobalProtect 6.3.0 through 6.3.3-h10 on Windows and macOS; through 6.3.3-h1 on Linux
Fixed versions6.0.13 or later on Windows and macOS; 6.0.11 or later on Linux, 6.2.8-h10 (6.2.8-948) or later on Windows and macOS; 6.3.3-h2 (6.3.3-c42) or later on Linux, 6.3.3-h11 (6.3.3-c1016) or later on Windows and macOS

Temporary risk reduction

No known workarounds exist for this issue. Users should apply the upgraded versions indicated by Palo Alto Networks to remediate the vulnerabilities.

Evidence and validation checklist

  • Palo Alto Networks official security advisory for CVE-2026-0251
  • Described impact and technical details of the local privilege escalation
  • Confirmed affected platforms and versions
  • Specified fixed versions available and upgrade recommendations
  • No known workarounds exist
  • No known exploitation reported

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source