CVE-2026-0298 PUBLISHED

GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

Assigner: palo_alto
Reserved: 03.11.2025 Published: 13.08.2026 Updated: 13.08.2026

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 5.2

Product Status

Vendor Palo Alto Networks
Product GlobalProtect App
Versions Default: unaffected
  • affected from 6.3.0 to 6.3.3-h14 (excl.)
  • affected from 6.2.0 to 6.2.8-h13 (excl.)
  • affected from 6.0.0 to 6.0.15 (excl.)
Vendor Palo Alto Networks
Product GlobalProtect App
Versions Default: unaffected
  • Version All is unaffected

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • our internal security research teams finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE

Impacts

  • CAPEC-242 Code Injection