Answer in brief
CVE-2026-0307 records a Unknown severity vulnerability in GlobalProtect App: Local Privilege Escalation Vulnerabilities. The current sources do not mark it as known exploited. The current feed maps Palo Alto Networks/GlobalProtect App (generic), Palo Alto Networks/GlobalProtect App (generic), Palo Alto Networks/GlobalProtect App (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Palo Alto Networks/GlobalProtect App (generic), Palo Alto Networks/GlobalProtect App (generic), Palo Alto Networks/GlobalProtect App (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Palo Alto Networks/GlobalProtect Appgeneric | >=6.3.0 <6.3.3-h15 || >=6.0.0 <6.0.15 | 6.3.3-h15, 6.0.15 |
| Palo Alto Networks/GlobalProtect Appgeneric | >=6.3.0 <6.3.3-h15 || >=6.2.0 <6.2.8-h14 || >=6.0.0 <6.0.15 | 6.3.3-h15, 6.2.8-h14, 6.0.15 |
| Palo Alto Networks/GlobalProtect Appgeneric | All | Not reported |
Published upstream
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 10, 2026
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This GlobalProtect app on iOS, Android and ChromeOS is not impacted.
Quoted source text, attributed separately from HOL analysis.