GlobalProtect App
CVE-2026-0298: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| GlobalProtect App (Windows) 6.3 | 6.3.3-h14 or later |
| GlobalProtect App (Windows) 6.2 | 6.2.8-h13 or later |
| GlobalProtect App (Windows) 6.0 | 6.0.15 or later |
| GlobalProtect App (Linux, macOS, Android, Chrome OS, iOS) | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Am I affected?
This issue is applicable only to devices configured to use SAML authentication in the GlobalProtect Connect Before Logon (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method) feature.
Workarounds
Customers can mitigate the risk of this issue by taking either of the following actions:
- Use Connect Before Logon (CBL (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method)) (https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-windows/use-connect-before-logon-followed-by-the-authentication-method) without SAML Authentication
- Use Pre-logon with machine certificate (https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/remote-access-vpn-with-pre-logon) instead of Connect Before Logon (CBL).
Exploitation
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.