What is CVE-2026-0298?
CVE-2026-0298 is an improper input validation vulnerability found in the Windows Pre-Logon Access Provider (PLAP) component of Palo Alto Networks GlobalProtect™ app. This flaw allows a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on the affected client. Applying the vendor's security patches immediately is strongly recommended.
Azərbaycanca: CVE-2026-0298, Palo Alto Networks GlobalProtect™ tətbiqinin Windows PLAP komponentində aşkar edilmiş improper input validation zəifliyidir. Bu boşluq man-in-the-middle (MitM) hücumçusuna hədəf cihazda SYSTEM səviyyəsində ixtiyari kod icra etməyə imkan verir. Təsirə məruz qalan sistemlərdə təhlükəsizlik yamalarının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which component of the Palo Alto Networks GlobalProtect™ app is affected by CVE-2026-0298?
The vulnerability affects the Windows PLAP (Pre-Logon Access Provider) component of the app.
What privilege level can an attacker achieve on a compromised device by exploiting CVE-2026-0298?
The attacker can execute arbitrary code with SYSTEM privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.