An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectâ„¢ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0298 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-13 03:16
Updated : 2026-09-10 17:01
NVD link : CVE-2026-0298
Mitre link : CVE-2026-0298
CVE.ORG link : CVE-2026-0298
JSON object : View
Products Affected
paloaltonetworks
- globalprotect
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
