CVE-2026-0297
Received Received - Intake

Buffer Overflow in Palo Alto Networks GlobalProtect App

Vulnerability report for CVE-2026-0297, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Palo Alto Networks, Inc.

Description

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
palo_alto_networks globalprotect to 6.3.3-h15 (exc)
palo_alto_networks globalprotect to 6.3.3-h14 (exc)
palo_alto_networks globalprotect to 6.3.5 (exc)
palo_alto_networks globalprotect to 6.2.8-h13 (exc)
palo_alto_networks globalprotect to 6.0.15 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-0297 is a buffer overflow vulnerability in the Palo Alto Networks GlobalProtect app that occurs during the UDP tunnel handshake process. It can be exploited by a man-in-the-middle attacker or rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges, including SYSTEM on Windows and root on macOS/Linux.

Detection Guidance

Detecting this vulnerability requires checking the installed version of the Palo Alto Networks GlobalProtect app against the affected versions. On Linux, run 'globalprotect version' or check package managers like 'dpkg -l | grep GlobalProtect' or 'rpm -qa | grep GlobalProtect'. On Windows, check 'Programs and Features' or run 'wmic product get name,version' in Command Prompt. For macOS, use 'system_profiler SPApplicationsDataType' or check the app version directly.

Impact Analysis

This vulnerability allows attackers to disrupt system processes and execute arbitrary code with high privileges. On Windows, this could lead to full system compromise. On macOS and Linux, it could grant root access. Attackers could install malware, steal data, or take control of the affected device.

Compliance Impact

The vulnerability could lead to unauthorized code execution with elevated privileges, potentially compromising sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (health information security) by enabling unauthorized access to personal or health data. Affected systems handling regulated data must address this flaw to maintain compliance.

Mitigation Strategies

Immediately upgrade the GlobalProtect app to a patched version: Linux to 6.3.3-h15 or later, macOS/Windows to 6.3.3-h14 or later, and mobile/ChromeOS to 6.3.5 or later. Alternatively, enforce SSL-only VPN connections or enable strict certificate checks as workarounds until upgrading is possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0297. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart