{"id":"CVE-2026-0295","title":"A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.\n\nThe GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…","summary":"A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.\n\nThe GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-362"],"vendor":"paloaltonetworks","product":"globalprotect","affected":["globalprotect < 6.0.15","globalprotect >= 6.2.0, < 6.2.8","globalprotect >= 6.3.0, < 6.3.3","globalprotect = 6.2.8","globalprotect = 6.3.3"],"patched":["globalprotect 6.3.3"],"published":"2026-08-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:12:10.887","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0295","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0295","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org","score-dispute"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-13T03:55:55.918274Z"},"scores":{"nvd":7,"cna":4.1},"ingestedAt":"2026-09-13T21:22:07.512Z","epss":0.00075,"epssPercentile":0.00101,"slug":"CVE-2026-0295","body":"## Overview\n\nA race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.\n\nThe GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.\n\n## Affected\n\n- `globalprotect < 6.0.15`\n- `globalprotect >= 6.2.0, < 6.2.8`\n- `globalprotect >= 6.3.0, < 6.3.3`\n- `globalprotect = 6.2.8`\n- `globalprotect = 6.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `globalprotect 6.3.3`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}