Palo Alto Networks GlobalProtect and Prisma Access Agent Vulnerabilities Disclosed

Palo Alto Networks GlobalProtect and Prisma Access Agent Vulnerabilities Disclosed

First seen 13 Aug 2026, 12:20 UTC security.paloaltonetworks.com 86% similarity 57.1

Article Content

Browse articles
ThreatCluster

Two local privilege escalation vulnerabilities were disclosed in Palo Alto Networks products. CVE-2026-0299 affects the GlobalProtect app, allowing local users on Windows, macOS, and Linux to escalate privileges to NT AUTHORITY\SYSTEM or root. CVE-2026-0294 affects the Prisma Access Agent app, enabling similar privilege escalation on Windows and macOS. Both vulnerabilities do not impact iOS, Android, or Chrome OS versions. Palo Alto Networks has not reported any known exploitation of these vulnerabilities. Users are advised to upgrade to the latest versions of the affected applications. The CVSS scores for GlobalProtect are 5.9 and 8.5, while Prisma Access Agent has scores of 6.0 and 8.5. No known workarounds exist for either issue.

Key Points: • CVE-2026-0299 in GlobalProtect allows privilege escalation on Windows, macOS, and Linux. • CVE-2026-0294 in Prisma Access Agent enables similar escalation on Windows and macOS. • Palo Alto Networks recommends immediate upgrades to mitigate these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-08-13
CVE-2026-0299 published
Local privilege escalation vulnerability in GlobalProtect app allows users to execute commands with elevated privileges on Windows, macOS, and Linux.
security.paloaltonetworks.com
2026-08-13
CVE-2026-0294 published
Privilege escalation vulnerability in Prisma Access Agent app allows code execution with elevated privileges on Windows and macOS.
security.paloaltonetworks.com

Community

Browse all →

Tracked Entities in This Story