CVE-2026-0267

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h1:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:macos:*:*

History

07 Jul 2026, 15:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://security.paloaltonetworks.com/CVE-2024-8687 - () https://security.paloaltonetworks.com/CVE-2024-8687 - Not Applicable
References () https://security.paloaltonetworks.com/CVE-2026-0267 - () https://security.paloaltonetworks.com/CVE-2026-0267 - Vendor Advisory, Mitigation
CPE cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h1:*:*:*:macos:*:*
First Time Paloaltonetworks
Paloaltonetworks globalprotect

10 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 22:16

Updated : 2026-07-07 15:01


NVD link : CVE-2026-0267

Mitre link : CVE-2026-0267

CVE.ORG link : CVE-2026-0267


JSON object : View

Products Affected

paloaltonetworks

  • globalprotect
CWE
CWE-532

Insertion of Sensitive Information into Log File