Description
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.

The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Published: 2026-08-13
Score: 4.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in the Palo Alto Networks GlobalProtect client on macOS allows a locally authenticated low‑privileged attacker to elevate privileges to root. The flaw, identified as a concurrency error (CWE‑362), grants the attacker full system control, enabling installation of malware, exfiltration of data, or tampering with critical system files. The impact is a complete compromise of the local machine, with potential cascading effects on network security if the device is part of a corporate environment.

Affected Systems

Affected are all macOS versions of the GlobalProtect App from 6.0.0 through 6.0.14, 6.2.0 through 6.2.8‑h12, and 6.3.0 through 6.3.3‑h13. The patching guidance specifies upgrading to 6.0.15 or later, 6.2.8‑h13 (6.2.8‑1045) or later, and 6.3.3‑h14 (6.3.3‑1121) or later. Linux, Windows, iOS, Android, Chrome OS, and other platforms are not affected.

Risk and Exploitability

The CVSS score of 4.1 indicates a moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, authenticated access, typically a user with restricted privileges on a macOS device. Because a race condition can be difficult to trigger reliably and no workaround exists, the risk is primarily higher for otherwise unattended devices where a malicious application or script can initiate the race.

Generated by OpenCVE AI on August 13, 2026 at 03:18 UTC.

Remediation

Vendor Workaround

No known workarounds or mitigations exist for this issue.


OpenCVE Recommended Actions

  • Upgrade the GlobalProtect App on macOS to a patched release (6.0.15 or later, 6.2.8‑h13 or later, or 6.3.3‑h14 or later).
  • Remove or isolate any older/unpatched GlobalProtect binaries from the system to prevent accidental use.
  • Enforce least‑privilege on macOS, ensuring local users do not have administrative rights beyond those required for their role.

Generated by OpenCVE AI on August 13, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Title GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
First Time appeared Palo Alto Networks
Palo Alto Networks globalprotect App
Weaknesses CWE-362
CPEs cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:macos:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:android:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:chrome_os:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:ios:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:linux:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:windows:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks globalprotect App
References
Metrics cvssV4_0

{'score': 4.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Globalprotect App
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T03:55:55.184Z

Reserved: 2025-11-03T20:44:53.142Z

Link: CVE-2026-0295

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:44.493

Modified: 2026-08-13T03:16:44.493

Link: CVE-2026-0295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:30:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')