GlobalProtect App: Local Privilege Escalation Vulnerabilities
Plan PatchCVSS 8.5CVE-2026-0299Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
Local privilege escalation vulnerabilities in Palo Alto Networks GlobalProtect app allow a non-administrative user to escalate privileges to SYSTEM (Windows), root (macOS/Linux), and execute arbitrary commands with full administrative rights. iOS, Android, and Chrome OS versions are not affected. Multiple versions across all major platforms are vulnerable; fixes are available for most configurations, but no patch exists for GlobalProtect 6.x on Linux.
What this means
What could happen
A user with regular (non-administrator) access to a Windows, macOS, or Linux workstation running GlobalProtect could escalate their privileges to full administrative control, allowing them to install malware, modify system settings, or access sensitive data on that device.
Who's at risk
IT departments and security teams managing remote workforce access via Palo Alto GlobalProtect on Windows, macOS, and Linux endpoints. Contractors, remote employees, or any user with local device access to a vulnerable version is at risk.
How it could be exploited
An attacker with local access to a vulnerable GlobalProtect installation can trigger a privilege escalation flaw to gain administrative or root privileges. No network access is required—only physical or prior remote access to the workstation.
Prerequisites
- Local user account on the workstation running GlobalProtect
- Vulnerable version of GlobalProtect App (specific versions vary by OS)
- Ability to execute code or interact with the system as a non-admin user
Local exploitation (requires device access)Low complexityNo authentication bypass requiredEscalates to administrative/rootAffects multiple operating systemsNo fix available for GlobalProtect 6.x on Linux
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (9)
8 with fix1 pending
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h15 on Linux6.3.3-h15 on Linux (ETA: 08/28)+
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on macOS6.3.3-h14 (6.3.3-1121) on macOS+
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on Windows6.3.3-h14 (6.3.3-1121) on Windows+
GlobalProtect AppAll on LinuxNo fix yet
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on macOS6.2.8-h13 (6.2.8-1045) on macOS+
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on Windows6.2.8-h13 (6.2.8-1045) on Windows+
GlobalProtect AppBelow 6.0.15 on Linux6.0.15 on Linux (ETA: 08/31)+
GlobalProtect AppBelow 6.0.15 on macOS6.0.15 on macOS (ETA: 08/31)+
Remediation & Mitigation
0/2
Do now
0/1HARDENINGFor GlobalProtect on Linux where no fix is available, restrict local login access to trusted administrators only and enforce host-based access controls or group policy to limit who can run privileged commands
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
GlobalProtect App
HOTFIXUpdate GlobalProtect App to version 6.3.3-h15 (Linux), 6.3.3-h14/6.3.3-1121 (macOS/Windows), or 6.2.8-h13/6.2.8-1045 (macOS/Windows legacy branch), or 6.0.15 (all platforms)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e55ae363-1ec0-42bd-9748-562cc6036e98Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.