{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apalo_alto_networksglobalprotect_app6.3.3linux/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:linux:*:*","cpe:2.3:a:palo_alto_networks:globalprotect_app:6.0.14:*:*:*:*:linux:*:*"],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GlobalProtect App (\u003c 6.3.3-h15, \u003c 6.2.8-h14, \u003c 6.0.15)","PAN-OS (12.2.0-12.2.2, 12.1.2-12.1.9, 11.2.0-11.2.13, 11.1.0-11.1.16, 10.2.0-10.2.18)","Prisma Access (12.1.2-12.1.*, 11.2.0-11.2.*, 10.2.0-10.2.*)","GlobalProtect App"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","privilege-escalation","endpoint"],"_cs_type":"threat","_cs_vendors":["Palo Alto Networks"],"content_html":"\u003cp\u003ePalo Alto Networks has disclosed multiple local privilege escalation vulnerabilities (CVE-2026-0307) affecting the GlobalProtect app across Windows, macOS, and Linux platforms. The issue stems from CWE-426, an untrusted search path vulnerability, which allows a local non-administrative user to manipulate the execution flow of the application to run arbitrary commands with elevated privileges (NT AUTHORITY\\SYSTEM on Windows and root on macOS/Linux).\u003c/p\u003e\n\u003cp\u003eThe vulnerability is categorized as Medium severity and is documented with a CVSS-BT score of 5.9. Exploitation requires local access, and Palo Alto Networks has confirmed that there is currently no evidence of malicious exploitation in the wild. Full remediation requires a coordinated update of both the client-side GlobalProtect application and the server-side infrastructure (PAN-OS or Prisma Access). iOS, Android, and ChromeOS versions of the app are not affected.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged local user to achieve full administrative control over the affected endpoint. This can lead to total system compromise, unauthorized data access, persistence installation, and further lateral movement within the network. The scope of impact is broad due to the ubiquity of GlobalProtect clients in enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the deployment of updated GlobalProtect client versions across all Windows, macOS, and Linux endpoints. Concurrently, schedule and execute upgrades for all affected PAN-OS and Prisma Access infrastructure components to ensure compatibility and full mitigation.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade GlobalProtect App on Linux, macOS, and Windows to the versions specified in the Palo Alto Networks advisory (e.g., 6.3.3-h15 or later).\u003c/li\u003e\n\u003cli\u003eUpdate all PAN-OS and Prisma Access environments to the patched versions listed in the Solution section of the source advisory to ensure the infrastructure components are no longer vulnerable.\u003c/li\u003e\n\u003cli\u003eAudit endpoint security logs for unauthorized process execution or unexpected binary loading from untrusted directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T12:54:58Z","date_published":"2026-09-09T18:57:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-globalprotect-lpe/","summary":"Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect application allow a local user to gain administrative privileges (SYSTEM/root) due to an untrusted search path issue.","title":"GlobalProtect App Local Privilege Escalation Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-09-globalprotect-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:linux:*:*","version":"https://jsonfeed.org/version/1.1"}