VYPR
Medium severityNVD Advisory· Published Jun 10, 2026

CVE-2026-0267

CVE-2026-0267

Description

A local information exposure vulnerability in Palo Alto Networks GlobalProtect app on macOS allows users to discover passcodes for disabling, disconnecting, or uninstalling the app.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local information exposure vulnerability in Palo Alto Networks GlobalProtect app on macOS allows users to discover passcodes for disabling, disconnecting, or uninstalling the app.

Vulnerability

An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on macOS. This issue affects deployments where features allowing users to disable, disconnect, or uninstall the GlobalProtect app with a passcode are enabled. Affected versions include GlobalProtect App 6.3 prior to 6.3.3-h1 and GlobalProtect App 6.2 prior to 6.2.8-h2 on macOS [2].

Exploitation

A local user with access to the affected macOS system can exploit this vulnerability. The attacker needs to be able to read specific files or logs generated by the GlobalProtect app to discover the configured passcodes. No network access, privileges beyond local user, or user interaction is required [2].

Impact

Successful exploitation allows a local user to obtain the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. With these passcodes, the user can bypass intended restrictions and perform these actions, potentially leading to a loss of confidentiality for the organization's network access policies [2].

Mitigation

Palo Alto Networks has released fixed versions of the GlobalProtect app. For macOS, GlobalProtect App 6.3 should be upgraded to version 6.3.3-h1 or later, and GlobalProtect App 6.2 should be upgraded to version 6.2.8-h2 or later. Palo Alto Networks is not aware of any malicious exploitation of this issue [2].

AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

1