Skip to content
Palo Alto NetworksCVE-2026-0307

Palo Alto Networks GlobalProtect App: privilege escalation

Medium5.9CVE-2026-0307 · Published Sep 10, 2026 · updated Sep 11, 2026

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This GlobalProtect app on iOS, Android and ChromeOS is not impacted.

Palo Alto Networks advisory

Affected versions

PackageAffectedFixed in
GlobalProtect App
Product
>= 6.3.0, < 6.3.3-h156.3.3-h15
>= 6.0.0, < 6.0.156.0.15
>= 6.3.0, < 6.3.3-h156.3.3-h15
>= 6.2.0, < 6.2.8-h146.2.8-h14
>= 6.0.0, < 6.0.156.0.15
all versionsNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-426

More Palo Alto Networks advisories

All Palo Alto Networks
Advisory
Palo Alto Networks Checkov by Prisma Cloud: code execution
Low2.4Sep 10
Palo Alto Networks Cortex XDR Broker VM: privilege escalation
Medium4.8Sep 10
Palo Alto Networks Checkov by Prisma Cloud: command injection
Low1.1Sep 10
Palo Alto Networks Cloud NGFW: buffer overflow
High7.2Sep 10
Palo Alto Networks Prisma: local user could bypass configured DLP policy...
Medium5.8Sep 10
Palo Alto Networks PAN-OS: cross-site scripting
Low1.1Sep 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.