CVE-2026-0298
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Description
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Weakness: CWE-94
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported products (2)
- Palo Alto Networks · GlobalProtect App
- Palo Alto Networks · GlobalProtect App — vendor states not affected
Credit
our internal security research teams
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App All on macOS No action needed. GlobalProtect App All on Linux No action needed. GlobalProtect App All on iOS No action needed. GlobalProtect App All on Android No action needed. GlobalProtect App All on Chrome OS No action needed.