GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

Plan PatchCVSS 7.7CVE-2026-0298Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

An improper input validation vulnerability in the Windows Pre-Logon Access Provider (PLAP) component of Palo Alto Networks GlobalProtect app allows a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges on affected Windows clients during the pre-logon phase. The vulnerability affects GlobalProtect app versions below 6.3.3-h14 (6.3.3-1121) on Windows and below 6.2.8-h13 (6.2.8-1045) on the 6.2.x branch. GlobalProtect on Linux, macOS, iOS, Android, and Chrome OS is not affected.

What this means
What could happen
An attacker on the network path between a Windows computer and GlobalProtect gateway could run code with system privileges during user logon, potentially installing malware, stealing credentials, or disrupting VPN authentication before the user logs in.
Who's at risk
Windows-based employees and remote workers who use Palo Alto Networks GlobalProtect app for VPN access, particularly those connecting before logging into their workstations. Organizations with PLAP-based pre-logon access policies are at higher risk. This affects any industry relying on remote access for fieldwork, support, or distributed operations.
How it could be exploited
An attacker positioned between the Windows client and the GlobalProtect gateway (e.g., on the same network or via DNS hijacking) intercepts the pre-logon authentication traffic and sends a malicious response to the Windows PLAP component, which fails to validate the input properly and executes arbitrary code with SYSTEM privileges.
Prerequisites
  • Network position on the path between Windows client and GlobalProtect gateway (man-in-the-middle capability)
  • GlobalProtect app version below 6.3.3-h14 on Windows (or below 6.2.8-h13 for legacy versions)
  • Pre-logon access provider (PLAP) feature enabled in GlobalProtect configuration
remotely exploitableno authentication requiredaffects critical logon phaseman-in-the-middle vectorCVSS 7.7 (high)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on Windows6.3.3-h14 (6.3.3-1121) on Windows+
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on Windows6.2.8-h13 (6.2.8-1045) on Windows+
Remediation & Mitigation
0/5
Do now
0/2
WORKAROUNDDisable Pre-Logon Access Provider (PLAP) and use Connect Before Logon (CBL) without SAML authentication instead
WORKAROUNDSwitch from Connect Before Logon (CBL) to Pre-logon with machine certificate authentication
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

GlobalProtect App
HOTFIXUpdate GlobalProtect app to version 6.3.3-h14 (6.3.3-1121) or later on all Windows clients
HOTFIXUpdate GlobalProtect app to version 6.2.8-h13 (6.2.8-1045) or later on Windows clients still on the 6.2.x branch
Long-term hardening
0/1
HARDENINGImplement network segmentation to restrict pre-logon gateway traffic from untrusted network segments
API: /api/v1/advisories/17a9fa2d-e861-4c0f-a1a9-c37e55c5dc1e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) | CVSS 7.7 - OTPulse