In plain language
What this advisory means
A security weakness in the Windows version of the Palo Alto Networks GlobalProtect app can allow a nearby attacker to take control of the affected device without needing the user to do anything. This issue happens only when the device uses a specific login method called SAML with the Connect Before Logon feature. The problem has been fixed in recent updates of the app, so users should upgrade to those versions to stay secure.
Technical explanation
How the issue affects the environment
CVE-2026-0298 is an improper input validation vulnerability in the Windows Pre-Logon Access Provider (PLAP) component of the GlobalProtect app on Windows. This flaw enables a man-in-the-middle attacker within adjacent network range to execute arbitrary code with SYSTEM privileges on the client device. The vulnerability affects only devices configured with SAML authentication under the Connect Before Logon (CBL) feature. Versions prior to 6.3.3-h14 on 6.3, 6.2.8-h13 on 6.2, and 6.0.15 on 6.0 branch releases are vulnerable. The vulnerability corresponds to CWE-94 (Code Injection) and CAPEC-242 (Code Injection). Palo Alto Networks reports no known exploitation in the wild and recommends upgrading to the fixed versions to mitigate risk.
Operational impact
Why teams should care
If exploited, the vulnerability can allow an attacker positioned within the local network ('adjacent' attacker) to execute code with the highest system privileges (SYSTEM) on affected Windows devices. This can compromise confidentiality and integrity of the device. No user interaction is required, making attacks potentially silent and impactful. The issue affects business operations relying on the GlobalProtect app's secure pre-logon connection, potentially allowing unauthorized access to sensitive systems.
Immediate action
Upgrade the GlobalProtect App on Windows to the fixed versions: 6.3.3-h14 or later for 6.3 branch, 6.2.8-h13 or later for 6.2 branch, and 6.0.15 or later for 6.0 branch. This will remediate the improper input validation vulnerability in the Windows Pre-Logon Access Provider component.
Affected and fixed releases
Temporary risk reduction
To mitigate risk without upgrading, users can disable SAML authentication in the Connect Before Logon feature, or use pre-logon with machine certificate instead of SAML-based Connect Before Logon.
Evidence and validation checklist
- Palo Alto Networks official advisory URL https://security.paloaltonetworks.com/CVE-2026-0298
- Description of vulnerability as improper input validation in Windows PLAP component
- Affected versions and fixed versions listed explicitly
- Exploit vector is adjacent network attacker, no user interaction needed
- Mitigation by upgrade or configuration changes explained
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
