CVE-2026-0267
MEDIUMGlobalProtect App: Information Exposure Vulnerability on macOS
Title source: cnaDescription
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://security.paloaltonetworks.com/CVE-2026-0267
Related related
https://security.paloaltonetworks.com/CVE-2024-8687
Scores
CVSS v4
4.4
EPSS
0.0011
EPSS Percentile
1.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (4)
Palo Alto Networks/GlobalProtect App
6.2.0 - 6.2.8-h2
Palo Alto Networks/GlobalProtect App
6.3.0 - 6.3.3-h1
Palo Alto Networks/GlobalProtect App
All
Palo Alto Networks/GlobalProtect UWP App
All
Published
Jun 10, 2026
Tracked Since
Jun 11, 2026