In plain language
What this advisory means
A security issue in the Palo Alto Networks GlobalProtect app lets a local user increase their access rights on a computer. This means someone with basic user access could gain full system control if they are on the affected Windows, macOS, or Linux device. The issue does not affect Android, iOS, Chrome OS, or UWP versions of the app. Users should upgrade their GlobalProtect app to the fixed versions to stop this vulnerability from being exploited.
Technical explanation
How the issue affects the environment
The vulnerability CVE-2026-0251 affects the GlobalProtect app on Windows, macOS, and Linux platforms. It involves multiple local privilege escalation flaws that allow a user with low privileges to escalate to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux. The exploitation vector is local with low complexity and no user interaction needed, allowing arbitrary command execution with administrator rights. The flaw stems from an untrusted search path weakness (CWE-426), potentially allowing execution of unauthorized code with elevated privileges. Palo Alto Networks has issued upgrades that address these issues in versions 6.0.13+, 6.2.8-h10+, and 6.3.3-h11+ depending on platform and series.
Operational impact
Why teams should care
If exploited, a local attacker could fully compromise affected systems, breaching confidentiality, integrity, and availability by executing commands as system or root user. This can lead to unauthorized data access, system changes, or denial of service, impacting business operations and security compliance. Since the vulnerability requires local access, insider threats or compromised endpoints are primary concerns. No known exploitation in the wild has been reported, but the risk remains significant without upgrading.
Immediate action
Upgrade your GlobalProtect app to the versions specified as fixed: 6.0.13 or newer on Windows and macOS, 6.0.11 or newer on Linux, 6.2.8-h10 or newer on Windows and macOS, 6.3.3-h11 or newer on Windows and macOS, and 6.3.3-h2 or newer on Linux to address these vulnerabilities.
Affected and fixed releases
Temporary risk reduction
No known workarounds exist for this issue. Users should apply the upgraded versions indicated by Palo Alto Networks to remediate the vulnerabilities.
Evidence and validation checklist
- Palo Alto Networks official security advisory for CVE-2026-0251
- Described impact and technical details of the local privilege escalation
- Confirmed affected platforms and versions
- Specified fixed versions available and upgrade recommendations
- No known workarounds exist
- No known exploitation reported
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
