GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Summary
| CVE | CVE-2026-0298 |
|---|---|
| State | PUBLISHED |
| Assigner | palo_alto |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-13 03:16:45 UTC |
| Updated | 2026-08-18 15:04:46 UTC |
| Description | An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected. |
Risk And Classification
Primary CVSS: v4.0 5.2 MEDIUM from [email protected]
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
EPSS: 0.001880000 probability, percentile 0.087270000 (date 2026-08-18)
Problem Types: CWE-94 | CWE-94 CWE-94 Improper Control of Generation of Code ('Code Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 5.2 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/C... |
| 4.0 | CNA | CVSS | 5.2 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/A... |
CVSS v4.0 Breakdown
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Palo Alto Networks | GlobalProtect App | affected 6.3.0 6.3.3-h14 custom | Windows |
| CNA | Palo Alto Networks | GlobalProtect App | affected 6.2.0 6.2.8-h13 custom | Windows |
| CNA | Palo Alto Networks | GlobalProtect App | affected 6.0.0 6.0.15 custom | Windows |
| CNA | Palo Alto Networks | GlobalProtect App | unaffected All custom | Linux, macOS, Android, Chrome OS, iOS |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.paloaltonetworks.com/CVE-2026-0298 | [email protected] | security.paloaltonetworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: our internal security research teams (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-08-12T16:00:00.000Z | Initial Publication |
Solutions
CNA: VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App All on macOS No action needed. GlobalProtect App All on Linux No action needed. GlobalProtect App All on iOS No action needed. GlobalProtect App All on Android No action needed. GlobalProtect App All on Chrome OS No action needed.
Workarounds
CNA: Customers can mitigate the risk of this issue by taking either of the following actions: 1. Use Connect Before Logon (CBL (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method)) (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method) without SAML Authentication 2. Use Pre-logon with machine certificate (https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/remote-access-vpn-with-pre-logon) instead of Connect Before Logon (CBL).
Exploits
CNA: Palo Alto Networks is not aware of any malicious exploitation of this issue.