In plain language
What this advisory means
A security flaw in the Palo Alto Networks GlobalProtect application lets local users gain administrative control on Windows, macOS, and Linux systems. This means someone with limited access could take over the device and run commands as an administrator. Devices running GlobalProtect on mobile platforms like iOS and Android are safe from this issue.
Technical explanation
How the issue affects the environment
The GlobalProtect app contains local privilege escalation vulnerabilities identified as CVE-2026-0299. An attacker who can access the system locally (physically or via remote terminal like SSH with low privileges) can exploit untrusted search paths to escalate privileges to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux. This allows execution of arbitrary commands with full administrative rights. The issue stems from improper handling of executable search paths in affected versions. No user interaction is required. The vulnerability does not affect GlobalProtect on iOS, Android, or Chrome OS.
Operational impact
Why teams should care
This vulnerability allows non-administrative users to gain full administrative control, risking unauthorized access to sensitive data, system integrity, and stability. Exploitation could lead to data breaches, disruption of services, or complete system compromise. Organizations using vulnerable GlobalProtect versions on Windows, macOS, or Linux may face significant security risks if not addressed.
Immediate action
Upgrade the GlobalProtect App to the fixed versions as specified for your platform. For Linux use version 6.3.3-h15 or newer, for Windows and macOS upgrade to 6.3.3-h14 (6.3.3-1121) or above, or to the appropriate patch for 6.2 and 6.0 series as listed by Palo Alto Networks. No special configuration is needed for the vulnerability to be present or fixed.
Affected and fixed releases
Temporary risk reduction
No known workarounds exist for this issue. Users should apply the upgrades promptly to prevent exploitation.
Evidence and validation checklist
- Local privilege escalation vulnerability in GlobalProtect app
- Affects Windows, macOS, and Linux versions as listed
- Does not affect iOS, Android or Chrome OS apps
- No user interaction required to exploit
- Exploitation possible via local or remote access with low privileges
- Palo Alto Networks recommends upgrading to specified fixed versions
- No workarounds currently available
- Severity rated medium with CVSS 5.9
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
