CVE-2026-0298: GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) (Severity: MEDIUM)
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect (Windows)to a version that resolves this vulnerability.Fixed in 6.0.15 - Configuration
Mitigate by using Connect Before Logon (CBL) without SAML Authentication.
Palo Alto Networks GlobalProtect (Windows) - authentication method Connect Before Logon (CBL) usage = without SAML Authentication - Configuration
Mitigate by using Pre-logon with machine certificate instead of Connect Before Logon (CBL).
Palo Alto Networks GlobalProtect (Windows) - pre-logon mode Pre-logon method = Use Pre-logon with machine certificate instead of Connect Before Logon (CBL)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0298?
CVE-2026-0298 has a severity rating of high with a score of 7.7.
How do I fix CVE-2026-0298?
To mitigate CVE-2026-0298, update the Palo Alto Networks GlobalProtect App to the latest version provided by the vendor.
What impact does CVE-2026-0298 have on systems?
CVE-2026-0298 allows a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges on affected Windows devices.
Which component is affected by CVE-2026-0298?
The vulnerability affects the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect app.
Can CVE-2026-0298 be exploited remotely?
Yes, CVE-2026-0298 can be exploited remotely due to its characteristics allowing man-in-the-middle attacks.