CVE-2026-0298
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-94
Control incorrecto de generación de código (Inyección de código)
Fecha de publicación:
13/08/2026
Última modificación:
13/08/2026
Descripción
*** Pendiente de traducción *** An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.<br />
<br />
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.



