CVE-2026-0298

GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

Severity
Medium 5.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
8.8th percentile
Discovered by
Vendor
Vendor-published field
Published
Aug 13, 2026
Assigned by palo_alto

Description

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Weakness: CWE-94

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported products (2)
  • Palo Alto Networks · GlobalProtect App
  • Palo Alto Networks · GlobalProtect App — vendor states not affected

Credit

our internal security research teams

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App All on macOS No action needed. GlobalProtect App All on Linux No action needed. GlobalProtect App All on iOS No action needed. GlobalProtect App All on Android No action needed. GlobalProtect App All on Chrome OS No action needed.

Something wrong here?