CVE-2026-0299: GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h15Fixed in 6.0.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (Linux) 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (Windows) 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (macOS) 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (Windows) 6.2to a version that resolves this vulnerability.Fixed in 6.2.8-h13 (6.2.8-1045) - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (macOS) 6.2to a version that resolves this vulnerability.Fixed in 6.2.8-h13 (6.2.8-1045) - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (Windows) 6.3to a version that resolves this vulnerability.Fixed in 6.3.3-h14 (6.3.3-1121) - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (macOS) 6.3to a version that resolves this vulnerability.Fixed in 6.3.3-h14 (6.3.3-1121) - Upgrade
Upgrade
Palo Alto Networks GlobalProtect App (Linux) 6.2/6.3to a version that resolves this vulnerability.Fixed in 6.3.3-h15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0299?
CVE-2026-0299 has a severity rating of high, with a score of 8.5.
How do I fix CVE-2026-0299?
To address CVE-2026-0299, ensure that you update the Palo Alto Networks GlobalProtect App to the latest version.
What systems are affected by CVE-2026-0299?
CVE-2026-0299 affects the Palo Alto Networks GlobalProtect App on Windows, macOS, and Linux systems.
What kind of vulnerability is CVE-2026-0299?
CVE-2026-0299 is a local privilege escalation vulnerability allowing non-administrative users to gain higher privileges.
What can an attacker achieve with CVE-2026-0299?
An attacker exploiting CVE-2026-0299 can execute arbitrary commands with administrative privileges on the affected systems.