Code Injection in GlobalProtect app for Windows - CVE-2026-0298

 

Code Injection in GlobalProtect app for Windows - CVE-2026-0298

Published: August 16, 2026


Vulnerability identifier: #VU143207
CSH Severity: High
CVSS v4: 9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-0298
CWE-ID: CWE-94
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the Windows Pre-Logon Access Provider (PLAP) component when processing SAML authentication in the Connect Before Logon feature. A remote attacker on the local network can perform a man-in-the-middle attack to execute arbitrary code.

Successful exploitation results in code execution with SYSTEM privileges and is applicable only to devices configured to use SAML authentication in the Connect Before Logon feature.


Affected software

GlobalProtect app for Windows

How to mitigate CVE-2026-0298

Install security update from vendor's website.

GlobalProtect app for Windows - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14

External References

Related Security Bulletins