An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-8687 | Not Applicable |
| https://security.paloaltonetworks.com/CVE-2026-0267 | Vendor Advisory Mitigation |
Configurations
Configuration 1 (hide)
|
History
07 Jul 2026, 15:01
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| References | () https://security.paloaltonetworks.com/CVE-2024-8687 - Not Applicable | |
| References | () https://security.paloaltonetworks.com/CVE-2026-0267 - Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h1:*:*:*:macos:*:* |
|
| First Time |
Paloaltonetworks
Paloaltonetworks globalprotect |
10 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 22:16
Updated : 2026-07-07 15:01
NVD link : CVE-2026-0267
Mitre link : CVE-2026-0267
CVE.ORG link : CVE-2026-0267
JSON object : View
Products Affected
paloaltonetworks
- globalprotect
CWE
CWE-532
Insertion of Sensitive Information into Log File
