Executive brief
The GlobalProtect app is a VPN client used by enterprises to provide secure remote access to corporate networks. Multiple local privilege escalation vulnerabilities allow a non-administrative user on Windows, macOS, or Linux to gain full administrative control (SYSTEM/root), enabling them to execute arbitrary commands, install malware, or compromise the entire endpoint.
Technical details
The vulnerability is a local privilege escalation (CWE-426: Untrusted Search Path) in the GlobalProtect app on Windows, macOS, and Linux. A low-privilege local user can escalate to NT AUTHORITY\SYSTEM on Windows or root on macOS/Linux without user interaction or special configuration. The attack requires local code execution capability but not elevated privileges initially. Patches are available: version 6.3.3-h15 or later for version 6.3, 6.2.8-h14 or later for version 6.2, and 6.0.15 or later for version 6.0. Note that both the GlobalProtect app and corresponding PAN-OS versions must be upgraded to fully remediate the issue.
Affected products
- Palo Alto Networks GlobalProtect 6.0.0-6.0.14, 6.2.0-6.2.8-h13, 6.3.0-6.3.3-h14 on Windows, macOS, and Linux
Timeline
- 2026-09-09: disclosed
- 2026-09-23: other: Advisory updated