AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-0298

MEDIUM · CVSS 5.2 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Windows version of the Palo Alto Networks GlobalProtect app, allowing a man-in-the-middle (MitM) attacker to exploit improper input validation to execute arbitrary code with SYSTEM privileges. This poses a significant risk to users on Windows devices, as it could lead to unauthorized access and control over the affected systems. Organizations using the GlobalProtect app on Windows should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-0298
Severity
MEDIUM
CVSS
5.2
EPSS
0.19%
Palo Alto Windows Linux Android Chrome

Original NVD Description

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectâ„¢ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.