Junglewise Threat Intelligence

CVE-2026-0267: Palo Alto Networks GlobalProtect app information exposure on macOS

CVE-2026-0267 · Severity: info · CVSS 4.4 · Published 2026-06-10

Technologies: Palo Alto Networks GlobalProtect App. Vendors: Palo Alto Networks.

Executive brief

A security issue in the Palo Alto Networks GlobalProtect app for macOS allows a person with local access to the computer to discover the administrative passcodes used to manage the software. Once these passcodes are known, the user can disable, disconnect, or uninstall the security software even if those actions were restricted by company policy. This could allow an employee or unauthorized user to bypass corporate security controls and network protections.

Technical details

An information exposure vulnerability (CWE-532) exists in the Palo Alto Networks GlobalProtect app for macOS where sensitive passcodes are inserted into log files or temporary files. A local attacker with low privileges can read these files to recover the configured passcodes for uninstalling, disabling, or disconnecting the GlobalProtect agent. This bypasses administrative restrictions intended to prevent users from tampering with the VPN client. The vulnerability specifically affects macOS deployments where the 'Allow User to Uninstall GlobalProtect App with Password' feature is enabled. Fixes are available in GlobalProtect app versions 6.3.3-h1 and 6.2.8-h2 for macOS.

Affected products

  • Palo Alto Networks GlobalProtect App 6.3 < 6.3.3-h1 on macOS, 6.2 < 6.2.8-h2 on macOS

Timeline

  • 2026-06-10: disclosed: Initial publication of the advisory
  • 2026-06-10: advisory

References

Related threats