CVE-2026-0267

MEDIUM

GlobalProtect App: Information Exposure Vulnerability on macOS

Title source: cna
STIX 2.1

Description

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.

References (2)

Core 2

Scores

CVSS v4 4.4
EPSS 0.0011
EPSS Percentile 1.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (4)
Palo Alto Networks/GlobalProtect App 6.2.0 - 6.2.8-h2
Palo Alto Networks/GlobalProtect App 6.3.0 - 6.3.3-h1
Palo Alto Networks/GlobalProtect App All
Palo Alto Networks/GlobalProtect UWP App All
Published Jun 10, 2026
Tracked Since Jun 11, 2026