Vulnerabilities
CVE-2026-0307: Palo Alto Networks GlobalProtect App Local Privilege Escalation
Palo Alto Networks has disclosed a medium-severity local privilege escalation vulnerability affecting the GlobalProtect app across Windows, macOS, and Linux. Low-privileged users can exploit this flaw to execute arbitrary commands with highest-level system privileges. Sysadmins must review patch availability and update client installations according to the vendor timeline.
What Happened
Palo Alto Networks published an advisory for CVE-2026-0307, a medium-severity local privilege escalation vulnerability residing in the GlobalProtect client application. Triggered via an untrusted search path weakness (CWE-426), the flaw enables a standard, non-administrative local user to elevate their execution context to NT AUTHORITY\SYSTEM on Windows hosts, and root privileges on macOS and Linux systems.
Impacted Systems and Scope
The vulnerability affects desktop and workstation operating systems running specific versions of the GlobalProtect app:
- GlobalProtect App 6.3: Versions up to 6.3.3-h14 (Linux, macOS, Windows)
- GlobalProtect App 6.2: Versions up to 6.2.8-h14 (macOS, Windows)
- GlobalProtect App 6.0: Versions up to 6.0.14 (Linux, macOS, Windows)
Mobile platforms, including iOS, Android, and ChromeOS, are entirely unaffected. No special configurations are required to trigger the exposure, and the attack vector is strictly local, requiring low privileges with no user interaction.
Defense and Mitigation Actions
Defenders and sysadmins should prepare to deploy patched versions of the GlobalProtect client as they become generally available through scheduled vendor releases:
- Upgrade GlobalProtect App 6.3 on Linux to version 6.3.3-h15 or later.
- Monitor vendor release schedules for Windows and macOS builds (targeted rollout through September and October).
- Ensure corresponding PAN-OS infrastructure and Prisma Access tenants are updated alongside client deployments where required.
Note that exploitation maturity is currently reported as untreported, and Palo Alto Networks is unaware of any active in-the-wild exploitation targeting this advisory.