CVE-2026-0295

GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

Severity
Medium 4.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
0.3th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 13, 2026
Assigned by palo_alto

Description

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Weakness: CWE-362

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported products (2)
  • Palo Alto Networks · GlobalProtect App
  • Palo Alto Networks · GlobalProtect App — vendor states not affected

Credit

Alex Bourla and Graham Brereton

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on macOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App on Linux No action needed. GlobalProtect App on Windows No action needed. GlobalProtect App on iOS No action needed. GlobalProtect App on Android No action needed. GlobalProtect App on Chrome OS No action needed.

Something wrong here?