CVE-2026-0295: GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect (macOS)to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect (macOS)to a version that resolves this vulnerability.Fixed in 6.2.8-h13 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect (macOS)to a version that resolves this vulnerability.Fixed in 6.3.3-h14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0295?
CVE-2026-0295 has a high severity score of 7.2.
How do I fix CVE-2026-0295?
To fix CVE-2026-0295, ensure that you update to the latest version of the Palo Alto Networks GlobalProtect App.
Who is affected by CVE-2026-0295?
CVE-2026-0295 affects users of the Palo Alto Networks GlobalProtect App on macOS.
What type of vulnerability is CVE-2026-0295?
CVE-2026-0295 is classified as a race condition vulnerability.
Can CVE-2026-0295 be exploited remotely?
No, CVE-2026-0295 can only be exploited by a locally authenticated user.