Junglewise Threat Intelligence

CVE-2026-0307: Palo Alto Networks GlobalProtect local privilege escalation

CVE-2026-0307 · Severity: info · CVSS 5.9 · Published 2026-09-10

Vendors: Palo Alto Networks.

Executive brief

The GlobalProtect app is a VPN client used by enterprises to provide secure remote access to corporate networks. Multiple local privilege escalation vulnerabilities allow a non-administrative user on Windows, macOS, or Linux to gain full administrative control (SYSTEM/root), enabling them to execute arbitrary commands, install malware, or compromise the entire endpoint.

Technical details

The vulnerability is a local privilege escalation (CWE-426: Untrusted Search Path) in the GlobalProtect app on Windows, macOS, and Linux. A low-privilege local user can escalate to NT AUTHORITY\SYSTEM on Windows or root on macOS/Linux without user interaction or special configuration. The attack requires local code execution capability but not elevated privileges initially. Patches are available: version 6.3.3-h15 or later for version 6.3, 6.2.8-h14 or later for version 6.2, and 6.0.15 or later for version 6.0. Note that both the GlobalProtect app and corresponding PAN-OS versions must be upgraded to fully remediate the issue.

Affected products

  • Palo Alto Networks GlobalProtect 6.0.0-6.0.14, 6.2.0-6.2.8-h13, 6.3.0-6.3.3-h14 on Windows, macOS, and Linux

Timeline

  • 2026-09-09: disclosed
  • 2026-09-23: other: Advisory updated

References