CVE-2026-0295

A race condition in the Palo Alto Networks GlobalProtectâ„¢ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h1:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h10:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h11:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h12:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h2:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h3:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h4:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h5:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h6:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h7:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h8:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h9:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h11:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h12:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h4:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h6:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h7:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h8:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h9:*:*:*:macos:*:*

History

No history.

Information

Published : 2026-08-13 03:16

Updated : 2026-09-10 17:12


NVD link : CVE-2026-0295

Mitre link : CVE-2026-0295

CVE.ORG link : CVE-2026-0295


JSON object : View

Products Affected

paloaltonetworks

  • globalprotect
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')