CVE-2026-0307: GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
This GlobalProtect app on iOS, Android and ChromeOS is not impacted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h15Fixed in 6.0.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h15Fixed in 6.2.8-h14Fixed in 6.0.15 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.7-h37 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h24 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.16-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h40 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h36 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.13-h12 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.6-h38 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.7-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.10-h33 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h21 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.7-h20 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.10-h14 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.4-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.7-h5 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.2.3 - Upgrade
Upgrade
GlobalProtect App (Linux)to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (Windows)to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (macOS)to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (Windows)to a version that resolves this vulnerability.Fixed in 6.2.8-h14 - Upgrade
Upgrade
GlobalProtect App (macOS)to a version that resolves this vulnerability.Fixed in 6.2.8-h14 - Upgrade
Upgrade
GlobalProtect App (Linux)to a version that resolves this vulnerability.Fixed in 6.3.3-h15 - Upgrade
Upgrade
GlobalProtect App (Windows)to a version that resolves this vulnerability.Fixed in 6.3.3-h15 - Upgrade
Upgrade
GlobalProtect App (macOS)to a version that resolves this vulnerability.Fixed in 6.3.3-h15 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16-h2 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.13-h2 - Upgrade
Upgrade
Prisma Accessto a version that resolves this vulnerability.Fixed in 10.2.10-h40 - Upgrade
Upgrade
Prisma Accessto a version that resolves this vulnerability.Fixed in 11.2.7-h20 - Upgrade
Upgrade
Prisma Accessto a version that resolves this vulnerability.Fixed in 12.1.7-h5
Event History
Frequently Asked Questions
Which platforms are affected?
The affected platforms are Windows, macOS, and Linux. The GlobalProtect app on iOS, Android, and ChromeOS is not impacted.
What access does an attacker need to exploit this issue?
An attacker must already have local, non-administrative access to the affected system. No user interaction is required after the attacker has that local access.
What level of access can exploitation provide?
Successful exploitation can allow arbitrary commands to run with administrative privileges: NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux.