Security Advisory Desk
mediumQCS priority 82/100Palo Alto Networks

CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) (Severity: MEDIUM)

A security flaw in the Windows version of Palo Alto Networks' GlobalProtect app allows attackers who can intercept network traffic to run harmful software on your computer before you log in. This problem only affects Windows devices using a specific login setup called SAML authentication with the Connect Before Logon feature. Other platforms like Linux, macOS, iOS, Android, and Chrome OS are safe. Palo Alto has fixed this in newer app versions and suggests either updating or changing login methods to avoid the risk.

Published 12/8/2026, 4:00:00 pmVerified 12/8/2026, 9:59:13 pmRevision 1
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security flaw in the Windows version of Palo Alto Networks' GlobalProtect app allows attackers who can intercept network traffic to run harmful software on your computer before you log in. This problem only affects Windows devices using a specific login setup called SAML authentication with the Connect Before Logon feature. Other platforms like Linux, macOS, iOS, Android, and Chrome OS are safe. Palo Alto has fixed this in newer app versions and suggests either updating or changing login methods to avoid the risk.

Technical explanation

How the issue affects the environment

The GlobalProtect app for Windows has an improper input validation vulnerability in its Pre-Logon Access Provider (PLAP) component, identified as CWE-94 (Code Injection). This flaw could be exploited by a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges on the client. The vulnerability is exploitable only on devices using SAML authentication with the Connect Before Logon (CBL) feature. The flaw does not require user interaction or privileges and leverages an adjacent network attack vector. Fixed versions for branches 6.3, 6.2, and 6.0 have been released to patch this issue. Versions on other operating systems are unaffected.

Operational impact

Why teams should care

If exploited, attackers could gain full control over affected Windows client systems before user login, potentially compromising sensitive corporate data and undermining system integrity. This can disrupt business operations and cause trust and compliance issues. Exploitation requires network position for man-in-the-middle attacks, limiting risk somewhat. Palo Alto Networks rates this vulnerability as Medium severity, reflecting moderate urgency for remediation.

Immediate action

Users should upgrade to the fixed GlobalProtect App versions for Windows: 6.3.3-h14 or later, 6.2.8-h13 or later, or 6.0.15 or later. These updates are available from Palo Alto Networks. Updating ensures the input validation vulnerability in the PLAP component is addressed.

Affected and fixed releases

Affected versionsGlobalProtect App for Windows versions 6.3.0 through 6.3.3-h13, 6.2.0 through 6.2.8-h12, and 6.0.0 through 6.0.14 when using SAML authentication with Connect Before Logon
Fixed versionsGlobalProtect App for Windows 6.3.3-h14 and later, 6.2.8-h13 and later, 6.0.15 and later

Temporary risk reduction

Alternatively, mitigate risk by configuring GlobalProtect Connect Before Logon without SAML authentication or by using pre-logon with machine certificate authentication instead of SAML-based Connect Before Logon. These configuration changes reduce exposure to this vulnerability.

Evidence and validation checklist

  • CVE-2026-0298 identifier confirmed by Palo Alto Networks Security Advisories.
  • Vulnerability affects GlobalProtect Windows client using Pre-Logon Access Provider (PLAP) component with SAML authentication.
  • Exploitation requires man-in-the-middle capability on an adjacent network vector.
  • Allows arbitrary code execution with SYSTEM privileges pre-logon.
  • Fixed versions and mitigation steps clearly specified.
  • No reported active exploitation as of advisory publication.

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source