Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)

A security weakness in Palo Alto Networks' GlobalProtect app lets a local user gain administrator-level control on Windows, macOS, and Linux systems. This means someone with limited access can run commands as if they were an administrator, potentially putting your system at risk. Mobile versions of the app are not affected. Updating to the latest versions provided by Palo Alto Networks removes this risk.

Published 12/9/2026, 12:30:00 amVerified 16/9/2026, 6:45:41 amRevision 2
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security weakness in Palo Alto Networks' GlobalProtect app lets a local user gain administrator-level control on Windows, macOS, and Linux systems. This means someone with limited access can run commands as if they were an administrator, potentially putting your system at risk. Mobile versions of the app are not affected. Updating to the latest versions provided by Palo Alto Networks removes this risk.

Technical explanation

How the issue affects the environment

The GlobalProtect app suffers from local privilege escalation vulnerabilities (CWE-426) via an untrusted search path. This flaw allows a local user with low privileges to escalate to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux by executing arbitrary commands with administrative rights. Exploitation requires local access (keyboard/console) or remote access methods like SSH and does not involve user interaction. The vulnerability affects specific versions on Windows, macOS, and Linux, but not on iOS, Android, or Chrome OS. Palo Alto Networks released patched versions to remediate the issue by correcting the search path handling.

Operational impact

Why teams should care

If exploited, this vulnerability allows an attacker with low privileged local access to gain full administrative control of affected systems. This risk undermines system integrity and confidentiality, potentially leading to unauthorized commands, data manipulation, or disruption of services. Organizations relying on GlobalProtect for secure network access should prioritize upgrading to maintain trusted security postures.

Immediate action

Upgrade affected GlobalProtect app versions on Windows, macOS, and Linux to the latest patched releases according to your version branch as detailed by Palo Alto Networks. No special configuration changes are needed for exposure mitigation.

Affected and fixed releases

Affected versionsGlobalProtect on Windows versions from 6.0.0 up to before 6.0.15, GlobalProtect on macOS versions from 6.0.0 up to before 6.0.15, GlobalProtect on Linux versions from 6.0.0 up to before 6.0.15, GlobalProtect on Windows versions from 6.2.0 up to before 6.2.8-h13, GlobalProtect on macOS versions from 6.2.0 up to before 6.2.8-h13, GlobalProtect on Linux versions from 6.2.0 to 6.3.3-h14 (pending), GlobalProtect on Windows versions from 6.3.0 up to before 6.3.3-h14, GlobalProtect on macOS versions from 6.3.0 up to before 6.3.3-h14
Fixed versionsGlobalProtect 6.0.15 and later for Windows, macOS, and Linux (with ETA for Linux 10/29), GlobalProtect 6.2.8-h13 and later for Windows and macOS, GlobalProtect 6.3.3-h14 (6.3.3-1121) and later for Windows and macOS, GlobalProtect 6.3.3-h15 and later for Linux (ETA 09/17)

Temporary risk reduction

No known workarounds or mitigations are available; apply the recommended upgrades as soon as possible.

Evidence and validation checklist

  • Palo Alto Networks Security Advisories entry for CVE-2026-0299
  • Details on affected and fixed versions with dates and upgrade paths
  • Description of vulnerability impact and attack complexity
  • Statements on lack of known exploit in the wild
  • No user interaction needed for exploitation
  • No workarounds available

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
CVE-2026-0299 GlobalProtect App: Local Privilege | Advisory | QCS