Executive brief
Palo Alto Networks GlobalProtect, a widely used VPN application for secure remote access, is affected by multiple vulnerabilities that allow a standard user to gain full administrative control over their computer. An attacker who already has basic access to a Windows, macOS, or Linux machine could exploit these flaws to bypass security restrictions, access sensitive files, or install malicious software. This could lead to a total compromise of the affected workstation and potentially serve as a jumping-off point for further attacks within the corporate network.
Technical details
The Palo Alto Networks GlobalProtect app for Windows, macOS, and Linux contains multiple local privilege escalation (LPE) vulnerabilities, including an untrusted search path (CWE-426) flaw. A local attacker with low-level privileges can exploit these issues to execute arbitrary code with SYSTEM (Windows) or root (macOS/Linux) privileges. The attack vector is local and requires no special configuration or user interaction. The vulnerabilities affect versions in the 6.0, 6.2, and 6.3 release cycles. Patches are available in versions 6.0.13, 6.2.8-h10, 6.3.3-h11 (Windows/macOS), and 6.0.11/6.3.3-h2 (Linux). Mobile versions (iOS, Android, Chrome OS) and the UWP app are not affected.
Affected products
- Palo Alto Networks GlobalProtect App Windows: 6.0.x < 6.0.13, 6.2.x < 6.2.8-h10, 6.3.x < 6.3.3-h11; macOS: 6.0.x < 6.0.13, 6.2.x < 6.2.8-h10, 6.3.x < 6.3.3-h11; Linux: 6.0.x < 6.0.11, 6.2.x < 6.3.3-h2, 6.3.x < 6.3.3-h2
Timeline
- 2026-05-13: advisory: Initial advisory published by Palo Alto Networks
- 2026-06-02: other: Advisory updated by vendor