In plain language
What this advisory means
A security flaw in the Windows version of Palo Alto Networks' GlobalProtect app allows attackers who can intercept network traffic to run harmful software on your computer before you log in. This problem only affects Windows devices using a specific login setup called SAML authentication with the Connect Before Logon feature. Other platforms like Linux, macOS, iOS, Android, and Chrome OS are safe. Palo Alto has fixed this in newer app versions and suggests either updating or changing login methods to avoid the risk.
Technical explanation
How the issue affects the environment
The GlobalProtect app for Windows has an improper input validation vulnerability in its Pre-Logon Access Provider (PLAP) component, identified as CWE-94 (Code Injection). This flaw could be exploited by a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges on the client. The vulnerability is exploitable only on devices using SAML authentication with the Connect Before Logon (CBL) feature. The flaw does not require user interaction or privileges and leverages an adjacent network attack vector. Fixed versions for branches 6.3, 6.2, and 6.0 have been released to patch this issue. Versions on other operating systems are unaffected.
Operational impact
Why teams should care
If exploited, attackers could gain full control over affected Windows client systems before user login, potentially compromising sensitive corporate data and undermining system integrity. This can disrupt business operations and cause trust and compliance issues. Exploitation requires network position for man-in-the-middle attacks, limiting risk somewhat. Palo Alto Networks rates this vulnerability as Medium severity, reflecting moderate urgency for remediation.
Immediate action
Users should upgrade to the fixed GlobalProtect App versions for Windows: 6.3.3-h14 or later, 6.2.8-h13 or later, or 6.0.15 or later. These updates are available from Palo Alto Networks. Updating ensures the input validation vulnerability in the PLAP component is addressed.
Affected and fixed releases
Temporary risk reduction
Alternatively, mitigate risk by configuring GlobalProtect Connect Before Logon without SAML authentication or by using pre-logon with machine certificate authentication instead of SAML-based Connect Before Logon. These configuration changes reduce exposure to this vulnerability.
Evidence and validation checklist
- CVE-2026-0298 identifier confirmed by Palo Alto Networks Security Advisories.
- Vulnerability affects GlobalProtect Windows client using Pre-Logon Access Provider (PLAP) component with SAML authentication.
- Exploitation requires man-in-the-middle capability on an adjacent network vector.
- Allows arbitrary code execution with SYSTEM privileges pre-logon.
- Fixed versions and mitigation steps clearly specified.
- No reported active exploitation as of advisory publication.
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
