Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)

A security flaw in the Palo Alto Networks GlobalProtect application lets local users gain administrative control on Windows, macOS, and Linux systems. This means someone with limited access could take over the device and run commands as an administrator. Devices running GlobalProtect on mobile platforms like iOS and Android are safe from this issue.

Published 12/8/2026, 4:00:00 pmVerified 12/8/2026, 9:59:02 pmRevision 1
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security flaw in the Palo Alto Networks GlobalProtect application lets local users gain administrative control on Windows, macOS, and Linux systems. This means someone with limited access could take over the device and run commands as an administrator. Devices running GlobalProtect on mobile platforms like iOS and Android are safe from this issue.

Technical explanation

How the issue affects the environment

The GlobalProtect app contains local privilege escalation vulnerabilities identified as CVE-2026-0299. An attacker who can access the system locally (physically or via remote terminal like SSH with low privileges) can exploit untrusted search paths to escalate privileges to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux. This allows execution of arbitrary commands with full administrative rights. The issue stems from improper handling of executable search paths in affected versions. No user interaction is required. The vulnerability does not affect GlobalProtect on iOS, Android, or Chrome OS.

Operational impact

Why teams should care

This vulnerability allows non-administrative users to gain full administrative control, risking unauthorized access to sensitive data, system integrity, and stability. Exploitation could lead to data breaches, disruption of services, or complete system compromise. Organizations using vulnerable GlobalProtect versions on Windows, macOS, or Linux may face significant security risks if not addressed.

Immediate action

Upgrade the GlobalProtect App to the fixed versions as specified for your platform. For Linux use version 6.3.3-h15 or newer, for Windows and macOS upgrade to 6.3.3-h14 (6.3.3-1121) or above, or to the appropriate patch for 6.2 and 6.0 series as listed by Palo Alto Networks. No special configuration is needed for the vulnerability to be present or fixed.

Affected and fixed releases

Affected versionsGlobalProtect App 6.3.0 through 6.3.3-h14 on Windows and macOS, GlobalProtect App 6.3.0 through 6.3.3 and 6.2.0 through 6.3.3 on Linux, GlobalProtect App 6.2.0 through 6.2.8-h12 on Windows and macOS, GlobalProtect App 6.0.0 through 6.0.14 on Windows, macOS, and Linux
Fixed versionsGlobalProtect App 6.3.3-h15 or later on Linux, GlobalProtect App 6.3.3-h14 (6.3.3-1121) or later on Windows and macOS, GlobalProtect App 6.2.8-h13 (6.2.8-1045) or later on Windows and macOS, GlobalProtect App 6.0.15 or later on Windows, macOS, and Linux

Temporary risk reduction

No known workarounds exist for this issue. Users should apply the upgrades promptly to prevent exploitation.

Evidence and validation checklist

  • Local privilege escalation vulnerability in GlobalProtect app
  • Affects Windows, macOS, and Linux versions as listed
  • Does not affect iOS, Android or Chrome OS apps
  • No user interaction required to exploit
  • Exploitation possible via local or remote access with low privileges
  • Palo Alto Networks recommends upgrading to specified fixed versions
  • No workarounds currently available
  • Severity rated medium with CVSS 5.9

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
CVE-2026-0299 GlobalProtect App: Local Privilege | Advisory | QCS