A serious vulnerability has been identified in the Palo Alto Networks GlobalProtect app, potentially allowing local users to gain elevated privileges on Windows, macOS, and Linux systems. This flaw, labeled CVE-2026-0251, enables non-administrative users to execute commands with the highest administrative rights, effectively granting them access as NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. Importantly, this vulnerability does not affect the GlobalProtect app versions on iOS, Android, Chrome OS, and the UWP app, and no special configuration is needed for the vulnerability to be exploited.

The severity of this issue is underscored by a CVSS Base Score of 8.5, indicating a high risk of exploitation. Despite this, there have been no reports of the vulnerability being maliciously exploited in the wild. Currently, there are no known workarounds available, leaving systems running the affected versions vulnerable until a patch is released.

Organizations using GlobalProtect should remain vigilant and prepare to apply updates as soon as they are made available by Palo Alto Networks. It is crucial to monitor for any suspicious activity that could indicate an attempt to exploit this flaw. System administrators are advised to review their security measures and ensure that they are ready to respond to any potential threats arising from this vulnerability.