{"id":"CVE-2026-0298","title":"An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbi…","summary":"An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbi…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"paloaltonetworks","product":"globalprotect","affected":["globalprotect >= 6.0.0, < 6.0.15","globalprotect >= 6.2.0, < 6.2.8","globalprotect >= 6.3.0, < 6.3.3","globalprotect = 6.0.15","globalprotect = 6.2.8","globalprotect = 6.3.3"],"patched":["globalprotect 6.3.3"],"published":"2026-08-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:01:09.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0298","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0298","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org","score-dispute"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-13T03:55:53.877148Z"},"scores":{"nvd":8.1,"cna":5.2},"ingestedAt":"2026-09-11T19:39:18.894Z","epss":0.00333,"epssPercentile":0.2672,"slug":"CVE-2026-0298","body":"## Overview\n\nAn improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.\n\nThe GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS  is not affected.\n\n## Affected\n\n- `globalprotect >= 6.0.0, < 6.0.15`\n- `globalprotect >= 6.2.0, < 6.2.8`\n- `globalprotect >= 6.3.0, < 6.3.3`\n- `globalprotect = 6.0.15`\n- `globalprotect = 6.2.8`\n- `globalprotect = 6.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `globalprotect 6.3.3`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}