Back

HIGH

GlobalProtect App: Privilege Escalation (PE) Vulnerability

Published Jul 9, 2025

Description

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Affected products

Remediation

Vendor solution

Version Minor Version Suggested Solution

GlobalProtect App 6.3 on macOS

6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later.

GlobalProtect App 6.3 on Windows

6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later.

GlobalProtect App 6.2 on macOS

6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later.

GlobalProtect App 6.2 on Windows

6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.1 on macOSUpgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later.GlobalProtect App 6.1 on WindowsUpgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later.GlobalProtect App 6.0 on macOSUpgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later.GlobalProtect App 6.0 on WindowsUpgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on Linux

6.2.0 through 6.2.7 Upgrade to 6.2.8 or later. GlobalProtect App 6.1 on LinuxUpgrade to 6.2.8 or later.GlobalProtect App 6.0 on LinuxUpgrade to 6.2.8 or later.GlobalProtect App on Android, Chrome OS, iOS No action needed.GlobalProtect UWP App No action needed.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Jul 9, 2025
Updated Feb 26, 2026
Reserved Dec 20, 2024
CISA Vulnrichment
Updated Jul 10, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a