4.1
CVE-2026-0295
- EPSS 0.08%
- Veröffentlicht 13.08.2026 01:57:22
- Zuletzt bearbeitet 18.08.2026 15:04:46
- CVE-Watchlists
- Unerledigt
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
≫
Produkt
GlobalProtect App
Default Statusunaffected
Version
6.3.0
Version <
6.3.3-h14 (6.3.3-1121)
Status
affected
Version
6.2.0
Version <
6.2.8-h13 (6.2.8-1045)
Status
affected
Version
6.0.0
Version <
6.0.15
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
GlobalProtect App
Default Statusunaffected
Version
All
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.003 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@paloaltonetworks.com | 4.1 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://security.paloaltonetworks.com/CVE-2026-0295