Description
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Published: 2026-08-13
Score: 5.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper input validation in the Windows Pre‑Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect App allows a man‑in‑the‑middle attacker to execute arbitrary code with SYSTEM privileges on an affected client. This flaw is a classic code‑injection weakness (CWE‑94). The impact is full system compromise on the victim machine, providing the attacker with the highest local privileges and the ability to run any code.

Affected Systems

Affected products are Palo Alto Networks GlobalProtect App on Windows. Versions 6.3.0 through 6.3.3‑h13, 6.2.0 through 6.2.8‑h12, and 6.0.0 through 6.0.14 are vulnerable. The app on Linux, macOS, iOS, Android, and Chrome‑OS is not affected.

Risk and Exploitability

The CVSS score is 5.2, indicating a moderate severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, a remote attacker positioned as a MitM in the network can exploit the PLAP to run code with SYSTEM privileges. Successful exploitation requires network access to the vulnerable client and the ability to manipulate its authentication traffic. The lack of an EPSS score and KEV listing suggest that the vulnerability is not currently widely exploited, but the potential for local privilege escalation remains.

Generated by OpenCVE AI on August 13, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied updates: upgrade to GlobalProtect App on Windows 6.3.3‑h14 or later, or 6.2.8‑h13 or later, or 6.0.15 or later, depending on the installed version.
  • If an upgrade cannot be applied immediately, re‑configure the client to use Connect Before Logon (CBL) without SAML authentication, or use pre‑logon authentication with a machine certificate instead of the vulnerable PLAP.
  • Restrict the PLAP exposure by ensuring the client only connects over secure, trusted networks and monitor for signs of a MitM attack to detect potential exploitation early.

Generated by OpenCVE AI on August 13, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Title GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
First Time appeared Palo Alto Networks
Palo Alto Networks globalprotect App
Weaknesses CWE-94
CPEs cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:windows:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.0:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.10:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.11:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.12:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.13:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.1:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.2:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.3:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.4:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.5:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.6:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.7:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.8:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.0:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.1:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Windows:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:android:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:chrome_os:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:ios:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:linux:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:all:*:macos:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks globalprotect App
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Globalprotect App
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T03:55:53.146Z

Reserved: 2025-11-03T20:44:56.118Z

Link: CVE-2026-0298

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:45.560

Modified: 2026-08-13T05:17:20.537

Link: CVE-2026-0298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:00:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')