SB20260816153 - Remote code execution in GlobalProtect app for Windows PLAP component
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Code Injection (CVE-ID: CVE-2026-0298)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the Windows Pre-Logon Access Provider (PLAP) component when processing SAML authentication in the Connect Before Logon feature. A remote attacker on the local network can perform a man-in-the-middle attack to execute arbitrary code.
Successful exploitation results in code execution with SYSTEM privileges and is applicable only to devices configured to use SAML authentication in the Connect Before Logon feature.
Remediation
Install update from vendor's website.