{"api_version":"1","generated_at":"2026-08-22T04:26:50+00:00","cve":"CVE-2026-0296","urls":{"html":"https://cve.report/CVE-2026-0296","api":"https://cve.report/api/cve/CVE-2026-0296.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0296","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0296"},"summary":{"title":"GlobalProtect App: Improper Certificate Validation Bypass Vulnerability","description":"Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.\n\nThe GlobalProtect app on iOS, Android, and Chrome OS is not affected.","state":"PUBLISHED","assigner":"palo_alto","published_at":"2026-08-13 03:16:44","updated_at":"2026-08-18 15:04:46"},"problem_types":["CWE-295","CWE-295 CWE-295 Improper Certificate Validation"],"metrics":[{"version":"4.0","source":"psirt@paloaltonetworks.com","type":"Secondary","score":"4.5","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","baseScore":4.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"USER","valueDensity":"DIFFUSE","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"4.5","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","data":{"Automatable":"NO","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":4.5,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"DIFFUSE","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"MODERATE"}}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0296","name":"https://security.paloaltonetworks.com/CVE-2026-0296","refsource":"psirt@paloaltonetworks.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0296","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0296","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"affected 6.3.0 6.3.3-h15 custom","platforms":["Linux"]},{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"affected 6.2.0 custom","platforms":["Linux"]},{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"affected 6.0.0 6.0.15 custom","platforms":["Linux"]},{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"affected 6.3.0 6.3.3-h14 custom","platforms":["macOS","Windows"]},{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"affected 6.2.0 6.2.8-h13 custom","platforms":["macOS","Windows"]},{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"affected 6.0.0 6.0.15 custom","platforms":["macOS","Windows"]},{"source":"CNA","vendor":"Palo Alto Networks","product":"GlobalProtect App","version":"unaffected All custom","platforms":["iOS","Android","Chrome OS"]}],"timeline":[{"source":"CNA","time":"2026-08-12T16:00:00.000Z","lang":"en","value":"Initial Publication."}],"solutions":[{"source":"CNA","title":"","value":"VERSION                              MINOR VERSION             SUGGESTED SOLUTION\nGlobalProtect App 6.3/6.2 on Linux   6.2.0 through 6.3.3-h14   Upgrade to 6.3.3-h15 or later.\nGlobalProtect App 6.0 on Linux       6.0.0 through 6.0.14      Upgrade to 6.0.15 or later.\nGlobalProtect App 6.3 on macOS       6.3.0 through 6.3.3-h13   Upgrade to 6.3.3-h14 (6.3.3-1121) or later.\nGlobalProtect App 6.2 on macOS       6.2.0 through 6.2.8-h12   Upgrade to 6.2.8-h13 (6.2.8-1045) or later.\nGlobalProtect App 6.0 on macOS       6.0.0 through 6.0.14      Upgrade to 6.0.15 or later.\nGlobalProtect App 6.3 on Windows     6.3.0 through 6.3.3-h13   Upgrade to 6.3.3-h14 (6.3.3-1121) or later.\nGlobalProtect App 6.2 on Windows     6.2.0 through 6.2.8-h12   Upgrade to 6.2.8-h13 (6.2.8-1045) or later.\nGlobalProtect App 6.0 on Windows     6.0.0 through 6.0.14      Upgrade to 6.0.15 or later.\nGlobalProtect App on iOS                                       No action needed.\nGlobalProtect App on Android                                   No action needed.\nGlobalProtect App on Chrome OS                                 No action needed.","time":"","lang":"eng"}],"workarounds":[{"source":"CNA","title":"","value":"No known workarounds or mitigations exist for this issue.","time":"","lang":"eng"}],"exploits":[{"source":"CNA","title":"","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.","time":"","lang":"en"}],"credits":[{"source":"CNA","value":"our internal security research teams","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"296","cve":"CVE-2026-0296","epss":"0.000930000","percentile":"0.006310000","score_date":"2026-08-18","updated_at":"2026-08-19 00:07:28"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-0296","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-13T13:29:34.520951Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-13T13:29:46.735Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.9:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c982:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c948:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c910:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c471:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c431:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c416:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c317:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c263:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c243:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:Linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:Linux:*:*"],"defaultStatus":"unaffected","platforms":["Linux"],"product":"GlobalProtect App","vendor":"Palo Alto Networks","versions":[{"changes":[{"at":"6.3.3-h15","status":"unaffected"}],"lessThan":"6.3.3-h15","status":"affected","version":"6.3.0","versionType":"custom"},{"status":"affected","version":"6.2.0","versionType":"custom"},{"changes":[{"at":"6.0.15","status":"unaffected"}],"lessThan":"6.0.15","status":"affected","version":"6.0.0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.9:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.9:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c982:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c982:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c948:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c948:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c910:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c910:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c471:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c471:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c431:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c431:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c416:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c416:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c317:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c317:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c263:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c263:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c243:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8-c243:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:Windows:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:macOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:Windows:*:*"],"defaultStatus":"unaffected","platforms":["macOS","Windows"],"product":"GlobalProtect App","vendor":"Palo Alto Networks","versions":[{"changes":[{"at":"6.3.3-h14","status":"unaffected"}],"lessThan":"6.3.3-h14","status":"affected","version":"6.3.0","versionType":"custom"},{"changes":[{"at":"6.2.8-h13","status":"unaffected"}],"lessThan":"6.2.8-h13","status":"affected","version":"6.2.0","versionType":"custom"},{"changes":[{"at":"6.0.15","status":"unaffected"}],"lessThan":"6.0.15","status":"affected","version":"6.0.0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:Chrome_OS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:iOS:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:Android:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:Chrome_OS:*:*"],"defaultStatus":"unaffected","platforms":["iOS","Android","Chrome OS"],"product":"GlobalProtect App","vendor":"Palo Alto Networks","versions":[{"status":"unaffected","version":"All","versionType":"custom"}]}],"configurations":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"No special configuration is required to be affected by this issue."}],"value":"No special configuration is required to be affected by this issue."}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:linux:*:*:*:*:*","versionEndExcluding":"6.3.3-h15","versionStartIncluding":"6.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:linux:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:linux:*:*:*:*:*","versionEndExcluding":"6.0.15","versionStartIncluding":"6.0.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:macos:*:*:*:*:*","versionEndExcluding":"6.3.3-h14","versionStartIncluding":"6.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:windows:*:*:*:*:*","versionEndExcluding":"6.3.3-h14","versionStartIncluding":"6.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:macos:*:*:*:*:*","versionEndExcluding":"6.2.8-h13","versionStartIncluding":"6.2.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:windows:*:*:*:*:*","versionEndExcluding":"6.2.8-h13","versionStartIncluding":"6.2.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:macos:*:*:*:*:*","versionEndExcluding":"6.0.15","versionStartIncluding":"6.0.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:windows:*:*:*:*:*","versionEndExcluding":"6.0.15","versionStartIncluding":"6.0.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:ios:*:*:*:*:*","vulnerable":false},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:android:*:*:*:*:*","vulnerable":false},{"criteria":"cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:chrome_os:*:*:*:*:*","vulnerable":false}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"our internal security research teams"}],"datePublic":"2026-08-12T16:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p></p><span>Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.</span><b><span><br></span><span><br></span></b><span>The GlobalProtect app on iOS, Android, and Chrome OS is not affected.</span><p></p>"}],"value":"Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.\n\nThe GlobalProtect app on iOS, Android, and Chrome OS is not affected."}],"exploits":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}],"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}],"impacts":[{"capecId":"CAPEC-94","descriptions":[{"lang":"en","value":"CAPEC-94 Man in the Middle Attack"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NO","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":4.5,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"DIFFUSE","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"MODERATE"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"CWE-295 Improper Certificate Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-13T01:59:45.972Z","orgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","shortName":"palo_alto"},"references":[{"tags":["vendor-advisory"],"url":"https://security.paloaltonetworks.com/CVE-2026-0296"}],"solutions":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"<table class=\"tbl\">\n  <thead>\n    <tr>\n      <th>Version</th>\n      <th>Minor Version</th>\n      <th>Suggested Solution</th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr>\n      <td>GlobalProtect App 6.3/6.2 on Linux</td>\n      <td>6.2.0 through 6.3.3-h14</td>\n      <td>Upgrade to 6.3.3-h15 or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.0 on Linux</td>\n      <td>6.0.0 through 6.0.14</td>\n      <td>Upgrade to 6.0.15 or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.3 on macOS</td>\n      <td>6.3.0 through 6.3.3-h13</td>\n      <td>Upgrade to 6.3.3-h14 (6.3.3-1121) or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.2 on macOS</td>\n      <td>6.2.0 through 6.2.8-h12</td>\n      <td>Upgrade to 6.2.8-h13 (6.2.8-1045) or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.0 on macOS</td>\n      <td>6.0.0 through 6.0.14</td>\n      <td>Upgrade to 6.0.15 or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.3 on Windows</td>\n      <td>6.3.0 through 6.3.3-h13</td>\n      <td>Upgrade to 6.3.3-h14 (6.3.3-1121) or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.2 on Windows</td>\n      <td>6.2.0 through 6.2.8-h12</td>\n      <td>Upgrade to 6.2.8-h13 (6.2.8-1045) or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App 6.0 on Windows</td>\n      <td>6.0.0 through 6.0.14</td>\n      <td>Upgrade to 6.0.15 or later.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App on iOS</td>\n      <td></td>\n      <td>No action needed.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App on Android</td>\n      <td></td>\n      <td>No action needed.</td>\n    </tr>\n    <tr>\n      <td>GlobalProtect App on Chrome OS</td>\n      <td></td>\n      <td>No action needed.</td>\n    </tr>\n  </tbody>\n</table>"}],"value":"VERSION                              MINOR VERSION             SUGGESTED SOLUTION\nGlobalProtect App 6.3/6.2 on Linux   6.2.0 through 6.3.3-h14   Upgrade to 6.3.3-h15 or later.\nGlobalProtect App 6.0 on Linux       6.0.0 through 6.0.14      Upgrade to 6.0.15 or later.\nGlobalProtect App 6.3 on macOS       6.3.0 through 6.3.3-h13   Upgrade to 6.3.3-h14 (6.3.3-1121) or later.\nGlobalProtect App 6.2 on macOS       6.2.0 through 6.2.8-h12   Upgrade to 6.2.8-h13 (6.2.8-1045) or later.\nGlobalProtect App 6.0 on macOS       6.0.0 through 6.0.14      Upgrade to 6.0.15 or later.\nGlobalProtect App 6.3 on Windows     6.3.0 through 6.3.3-h13   Upgrade to 6.3.3-h14 (6.3.3-1121) or later.\nGlobalProtect App 6.2 on Windows     6.2.0 through 6.2.8-h12   Upgrade to 6.2.8-h13 (6.2.8-1045) or later.\nGlobalProtect App 6.0 on Windows     6.0.0 through 6.0.14      Upgrade to 6.0.15 or later.\nGlobalProtect App on iOS                                       No action needed.\nGlobalProtect App on Android                                   No action needed.\nGlobalProtect App on Chrome OS                                 No action needed."}],"source":{"discovery":"INTERNAL"},"timeline":[{"lang":"en","time":"2026-08-12T16:00:00.000Z","value":"Initial Publication."}],"title":"GlobalProtect App: Improper Certificate Validation Bypass Vulnerability","workarounds":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"No known workarounds or mitigations exist for this issue."}],"value":"No known workarounds or mitigations exist for this issue."}],"x_affectedList":["GlobalProtect App 6.3.3","GlobalProtect App 6.3.2","GlobalProtect App 6.3.1","GlobalProtect App 6.3.0","GlobalProtect App 6.3","GlobalProtect App 6.2.9","GlobalProtect App 6.2.8-c982","GlobalProtect App 6.2.8-c948","GlobalProtect App 6.2.8-c910","GlobalProtect App 6.2.8-c471","GlobalProtect App 6.2.8-c431","GlobalProtect App 6.2.8-c416","GlobalProtect App 6.2.8-c317","GlobalProtect App 6.2.8-c263","GlobalProtect App 6.2.8-c243","GlobalProtect App 6.2.8","GlobalProtect App 6.2.7","GlobalProtect App 6.2.6","GlobalProtect App 6.2.4","GlobalProtect App 6.2.3","GlobalProtect App 6.2.2","GlobalProtect App 6.2.1","GlobalProtect App 6.2.0","GlobalProtect App 6.2","GlobalProtect App 6.0.14","GlobalProtect App 6.0.13","GlobalProtect App 6.0.12","GlobalProtect App 6.0.11","GlobalProtect App 6.0.10","GlobalProtect App 6.0.8","GlobalProtect App 6.0.7","GlobalProtect App 6.0.6","GlobalProtect App 6.0.5","GlobalProtect App 6.0.4","GlobalProtect App 6.0.3","GlobalProtect App 6.0.2","GlobalProtect App 6.0.1","GlobalProtect App 6.0.0","GlobalProtect App 6.0"],"x_cpeGeneratedAt":"2026-08-12T02:10:58.092Z","x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","assignerShortName":"palo_alto","cveId":"CVE-2026-0296","datePublished":"2026-08-13T01:59:45.972Z","dateReserved":"2025-11-03T20:44:53.961Z","dateUpdated":"2026-08-13T13:29:46.735Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-13 03:16:44","lastModifiedDate":"2026-08-18 15:04:46","problem_types":["CWE-295","CWE-295 CWE-295 Improper Certificate Validation"],"metrics":{"cvssMetricV40":[{"source":"psirt@paloaltonetworks.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","baseScore":4.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"USER","valueDensity":"DIFFUSE","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T13:29:34.520951Z","id":"CVE-2026-0296","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"296","Ordinal":"1","Title":"GlobalProtect App: Improper Certificate Validation Bypass Vulner","CVE":"CVE-2026-0296","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"296","Ordinal":"1","NoteData":"Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.\n\nThe GlobalProtect app on iOS, Android, and Chrome OS is not affected.","Type":"Description","Title":"GlobalProtect App: Improper Certificate Validation Bypass Vulner"}]}}}