CVE-2026-0298: GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App for Windowsto a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App for Windowsto a version that resolves this vulnerability.Fixed in 6.2.8-h13 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App for Windowsto a version that resolves this vulnerability.Fixed in 6.3.3-h14 - Configuration
Use Connect Before Logon (CBL) without SAML Authentication.
GlobalProtect App for Windows Connect Before Logon (CBL) authentication = without SAML Authentication - Configuration
Use Pre-logon with a machine certificate instead of Connect Before Logon (CBL).
GlobalProtect App for Windows Pre-logon authentication = machine certificate
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0298?
CVE-2026-0298 has a severity rating of high with a score of 7.7.
How do I fix CVE-2026-0298?
To mitigate CVE-2026-0298, update the Palo Alto Networks GlobalProtect App to the latest version provided by the vendor.
What impact does CVE-2026-0298 have on systems?
CVE-2026-0298 allows a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges on affected Windows devices.
Which component is affected by CVE-2026-0298?
The vulnerability affects the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect app.
Can CVE-2026-0298 be exploited remotely?
Yes, CVE-2026-0298 can be exploited remotely due to its characteristics allowing man-in-the-middle attacks.