Palo Alto Networks GlobalProtect™ 应用程序中存在多个本地权限提升漏洞,允许本地用户将权限提升至 Windows 上的 NT AUTHORITY\SYSTEM,以及在 macOS 和 Linux 上的 root 权限。这使得非管理员用户能够以管理员权限执行任意命令。 该 GlobalProtect 应用程序在 iOS、Android 和 ChromeOS 平台上不受此问题影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | 6.3.0 ~ 6.3.3-h15 |
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Linux:*:*
|
|
| Palo Alto Networks | GlobalProtect App | 6.3.0 ~ 6.3.3-h15 |
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:macOS:*:*
|
|
| Palo Alto Networks | GlobalProtect App | All |
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:iOS:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0306 | 5.8 MEDIUM | Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows |
| CVE-2026-0310 | 5.2 MEDIUM | PAN-OS: Buffer Overflow Vulnerability via XML Processing |
| CVE-2026-0304 | 4.8 MEDIUM | Cortex XDR Broker VM: Privilege Escalation Vulnerability |
| CVE-2026-0305 | 4.3 MEDIUM | Prisma Access Agent: Information Disclosure Vulnerability on Linux |
| CVE-2026-0309 | 4.0 MEDIUM | PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration |
| CVE-2026-0303 | 2.4 LOW | Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File |
| CVE-2026-0302 | 1.1 LOW | Checkov by Prisma Cloud: OS Command Injection Vulnerability |
| CVE-2026-0308 | 0.4 LOW | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface |
No comments yet