CVE-2026-0298 MEDIUM

CVE-2026-0298: GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

Vendor Palo Alto Networks
Product GlobalProtect App
Weakness CWE-94 · Code injection
Published August 13, 2026
Last update August 13, 2026

CVSS base score

5.2/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

What the vulnerability does

01Description

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated

Related vulnerabilities

04Related CVE