Untrusted search path in Palo Alto Networks, Inc. products - CVE-2026-0299

 

Untrusted search path in Palo Alto Networks, Inc. products - CVE-2026-0299

Published: August 16, 2026


Vulnerability identifier: #VU143206
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0299
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to an untrusted search path in the GlobalProtect app when loading executables or libraries on a local system. A local user can place a malicious executable or library in a searched path to escalate privileges.

This issue can lead to execution of arbitrary commands with administrative privileges, including NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux.


Affected software

GlobalProtect App for Linux
GlobalProtect App for macOS
GlobalProtect app for Windows

How to mitigate CVE-2026-0299

Install security update from vendor's website.

GlobalProtect App for Linux - addressed in versions 6.0.15, 6.3.3-h15
GlobalProtect App for macOS - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14
GlobalProtect app for Windows - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14

External References

Related Security Bulletins