CVE-2026-0298

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectâ„¢ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.0.15:*:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h10:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h11:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h12:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h2:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h3:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h4:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h5:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h6:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h7:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h8:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h9:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h11:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h12:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h4:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h6:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h7:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h8:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h9:*:*:*:windows:*:*

History

No history.

Information

Published : 2026-08-13 03:16

Updated : 2026-09-10 17:01


NVD link : CVE-2026-0298

Mitre link : CVE-2026-0298

CVE.ORG link : CVE-2026-0298


JSON object : View

Products Affected

paloaltonetworks

  • globalprotect
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')