GlobalProtect App: Local Privilege Escalation Vulnerabilities
Plan PatchCVSS 8.5CVE-2026-0307Sep 9, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
Multiple local privilege escalation vulnerabilities in Palo Alto Networks GlobalProtect app allow a local user to escalate privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. A non-administrative user can execute arbitrary commands with administrative privileges. GlobalProtect app on iOS, Android, and ChromeOS is not affected.
What this means
What could happen
A regular user on an employee's Windows, macOS, or Linux laptop running GlobalProtect can escalate to full administrative control and execute any command, potentially compromising credentials, installing malware, or accessing sensitive data stored locally.
Who's at risk
This affects any organization using Palo Alto GlobalProtect on employee laptops, workstations, and remote access devices running Windows, macOS, or Linux. It is particularly relevant for utilities, water authorities, and other critical infrastructure organizations where employees use remote access for OT network management or monitoring. Affected personnel include employees using those laptops for corporate or OT system access.
How it could be exploited
An attacker with local access to an employee's laptop or workstation where GlobalProtect is installed can run a privilege escalation exploit locally to gain administrative rights. No network access or authentication beyond local login is needed. Once escalated, the attacker has full system access.
Prerequisites
- Local user account on the device running vulnerable GlobalProtect (Windows, macOS, or Linux)
- Vulnerable GlobalProtect version installed (below 6.3.3-h15 on Linux/macOS/Windows, below 6.0.15 on Linux/macOS/Windows, or below 6.2.8-h14 on macOS/Windows)
local privilege escalationno authentication required beyond local loginlow complexityaffects remote access security postureaffects employee devices and workstations
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h15 on Linux (ETA: 09/17)6.3.3-h15 on Linux (ETA: 09/17)+
GlobalProtect AppBelow 6.3.3-h15 on macOS (ETA: 09/28)6.3.3-h15 on macOS (ETA: 09/28)+
GlobalProtect AppBelow 6.3.3-h15 on Windows (ETA: 09/28)6.3.3-h15 on Windows (ETA: 09/28)+
GlobalProtect AppBelow 6.0.15 on Linux (ETA: 09/28)6.0.15 on Linux (ETA: 09/28)+
GlobalProtect AppBelow 6.0.15 on macOS (ETA: 09/28)6.0.15 on macOS (ETA: 09/28)+
GlobalProtect AppBelow 6.0.15 on Windows (ETA: 10/29)6.0.15 on Windows (ETA: 10/29)+
GlobalProtect AppBelow 6.2.8-h14 on macOS6.2.8-h14 on macOS+
GlobalProtect AppBelow 6.2.8-h14 on Windows6.2.8-h14 on Windows+
Remediation & Mitigation
0/5
Do now
0/1HARDENINGInventory all deployed GlobalProtect versions across Windows, macOS, and Linux endpoints to identify which devices require patching
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
GlobalProtect App
HOTFIXUpdate GlobalProtect App to version 6.3.3-h15 or later on Linux (target: 09/17), macOS (target: 09/28), or Windows (target: 09/28)
HOTFIXUpdate GlobalProtect App to version 6.0.15 or later on Linux (target: 09/28), macOS (target: 09/28), or Windows (target: 10/29)
HOTFIXUpdate GlobalProtect App to version 6.2.8-h14 or later on macOS or Windows
Long-term hardening
0/1HARDENINGRestrict physical or remote access to employee workstations and enforce strong endpoint authentication (full-disk encryption, login passwords) to reduce risk of local exploitation
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ed78ce96-1fab-4a57-a2bf-e412d7ccdc0bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.