← All Advisories

Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.8

Last refreshed2026-09-26

Status: NEW  |  Advisory ID: CVE-2026-0251

Key Details

CVECVE-2026-0251
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPalo Alto Networks GlobalProtect
Classified asCWE-426 (Untrusted Search Path)
Exploitation prediction (EPSS)0.18% probability of exploitation in the next 30 days (7% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksGlobalProtect
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

What to Do

Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0251
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0251
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0251