Security Advisory Desk
mediumQCS priority 82/100Palo Alto Networks

CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) (Severity: MEDIUM)

A security weakness in the Windows version of the Palo Alto Networks GlobalProtect app can allow a nearby attacker to take control of the affected device without needing the user to do anything. This issue happens only when the device uses a specific login method called SAML with the Connect Before Logon feature. The problem has been fixed in recent updates of the app, so users should upgrade to those versions to stay secure.

Published 12/9/2026, 12:30:00 amVerified 16/9/2026, 6:45:41 amRevision 2
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security weakness in the Windows version of the Palo Alto Networks GlobalProtect app can allow a nearby attacker to take control of the affected device without needing the user to do anything. This issue happens only when the device uses a specific login method called SAML with the Connect Before Logon feature. The problem has been fixed in recent updates of the app, so users should upgrade to those versions to stay secure.

Technical explanation

How the issue affects the environment

CVE-2026-0298 is an improper input validation vulnerability in the Windows Pre-Logon Access Provider (PLAP) component of the GlobalProtect app on Windows. This flaw enables a man-in-the-middle attacker within adjacent network range to execute arbitrary code with SYSTEM privileges on the client device. The vulnerability affects only devices configured with SAML authentication under the Connect Before Logon (CBL) feature. Versions prior to 6.3.3-h14 on 6.3, 6.2.8-h13 on 6.2, and 6.0.15 on 6.0 branch releases are vulnerable. The vulnerability corresponds to CWE-94 (Code Injection) and CAPEC-242 (Code Injection). Palo Alto Networks reports no known exploitation in the wild and recommends upgrading to the fixed versions to mitigate risk.

Operational impact

Why teams should care

If exploited, the vulnerability can allow an attacker positioned within the local network ('adjacent' attacker) to execute code with the highest system privileges (SYSTEM) on affected Windows devices. This can compromise confidentiality and integrity of the device. No user interaction is required, making attacks potentially silent and impactful. The issue affects business operations relying on the GlobalProtect app's secure pre-logon connection, potentially allowing unauthorized access to sensitive systems.

Immediate action

Upgrade the GlobalProtect App on Windows to the fixed versions: 6.3.3-h14 or later for 6.3 branch, 6.2.8-h13 or later for 6.2 branch, and 6.0.15 or later for 6.0 branch. This will remediate the improper input validation vulnerability in the Windows Pre-Logon Access Provider component.

Affected and fixed releases

Affected versionsGlobalProtect App 6.3.0 to 6.3.3-h13 on Windows, GlobalProtect App 6.2.0 to 6.2.8-h12 on Windows, GlobalProtect App 6.0.0 to 6.0.14 on Windows
Fixed versionsGlobalProtect App 6.3.3-h14 (6.3.3-1121) on Windows, GlobalProtect App 6.2.8-h13 (6.2.8-1045) on Windows, GlobalProtect App 6.0.15 on Windows

Temporary risk reduction

To mitigate risk without upgrading, users can disable SAML authentication in the Connect Before Logon feature, or use pre-logon with machine certificate instead of SAML-based Connect Before Logon.

Evidence and validation checklist

  • Palo Alto Networks official advisory URL https://security.paloaltonetworks.com/CVE-2026-0298
  • Description of vulnerability as improper input validation in Windows PLAP component
  • Affected versions and fixed versions listed explicitly
  • Exploit vector is adjacent network attacker, no user interaction needed
  • Mitigation by upgrade or configuration changes explained

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
CVE-2026-0298 GlobalProtect App: Code Execution | Advisory | QCS