CVE-2026-0295

NONE
CVSS v3
CVSS v2
0.08% EPSS (exploit probability)
CWE-362CWE

Description

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.

The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references