CVE-2026-0251: GlobalProtect App: Local Privilege Escalation Vulnerabilities
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h11Fixed in 6.2.8-h10Fixed in 6.0.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h2Fixed in 6.0.11 - Upgrade
Upgrade
GlobalProtect App 6.0 (Linux)to a version that resolves this vulnerability.Fixed in 6.0.11 - Upgrade
Upgrade
GlobalProtect App 6.0 (Windows)to a version that resolves this vulnerability.Fixed in 6.0.13 - Upgrade
Upgrade
GlobalProtect App 6.0 (macOS)to a version that resolves this vulnerability.Fixed in 6.0.13 - Upgrade
Upgrade
GlobalProtect App 6.2 (Linux)to a version that resolves this vulnerability.Fixed in 6.3.3-h2 (6.3.3-42) - Upgrade
Upgrade
GlobalProtect App 6.2 (Windows)to a version that resolves this vulnerability.Fixed in 6.2.8-h10 (6.2.8-948) - Upgrade
Upgrade
GlobalProtect App 6.2 (macOS)to a version that resolves this vulnerability.Fixed in 6.2.8-h10 (6.2.8-948) - Upgrade
Upgrade
GlobalProtect App 6.3 (Linux)to a version that resolves this vulnerability.Fixed in 6.3.3-h2 (6.3.3-42) - Upgrade
Upgrade
GlobalProtect App 6.3 (Windows)to a version that resolves this vulnerability.Fixed in 6.3.3-h11 - Upgrade
Upgrade
GlobalProtect App 6.3 (macOS)to a version that resolves this vulnerability.Fixed in 6.3.3-h11
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0251?
The severity of CVE-2026-0251 is classified as medium.
How do I fix CVE-2026-0251?
To fix CVE-2026-0251, ensure you update the Palo Alto Networks GlobalProtect app to the latest version.
Which platforms are affected by CVE-2026-0251?
CVE-2026-0251 affects the Palo Alto Networks GlobalProtect app on Windows, macOS, and Linux.
What type of vulnerability is CVE-2026-0251?
CVE-2026-0251 is classified as a local privilege escalation vulnerability.
What could an attacker gain from CVE-2026-0251?
An attacker exploiting CVE-2026-0251 could escalate their privileges to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux.