Skip to finding
important · Privilege — GlobalProtect

A normal GlobalProtect user can execute commands as SYSTEM or root across three desktop platforms.

Affects

Palo Alto Networks GlobalProtect, the enterprise VPN and endpoint-access client for Windows, macOS, and Linux.

A non-administrative user influences a search path consumed by a privileged component, which resolves attacker-controlled content as SYSTEM on Windows or root on macOS and Linux.

Detail and 1 source

Only the 6.2 Windows and macOS fixes were already available on September 10; several other platform or release fixes still had future dates.

Chain to watch
A non-administrative user influences a GlobalProtect search path.→↓A privileged component resolves attacker-controlled content.→↓Commands run as SYSTEM or root.→↓Coverage remains incomplete across the affected platform and release matrix.
Unverified chainInventory GlobalProtect versions by platform and verify each platform-specific fixed release rather than treating the 6.2 Windows and macOS release as universal coverage.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026