GlobalProtect Buffer Overflow Enables MitM Priv Esc
CVE-2026-0297 Published on August 13, 2026
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Vulnerability Analysis
Timeline
Initial Publication.
Weakness Type
What is a Memory Corruption Vulnerability?
The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.
CVE-2026-0297 has been classified to as a Memory Corruption vulnerability or weakness.
Products Associated with CVE-2026-0297
Want to know whenever a new CVE is published for Palo Alto Networks Globalprotect App? stack.watch will email you.
Affected Versions
Palo Alto Networks GlobalProtect App:- Version 6.3.0 and below 6.3.3-h15 is affected.
- Version 6.2.0 is affected.
- Version 6.0.0 and below 6.0.15 is affected.
- Version 6.3.0 and below 6.3.3-h14 is affected.
- Version 6.2.0 and below 6.2.8-h13 is affected.
- Version 6.0.0 and below 6.0.15 is affected.
- Version 6.3.0 and below 6.3.5 is affected.
- Version 6.0.0 and below 6.0.15 is affected.