A security researcher has disclosed five high-risk vulnerabilities in Palo Alto Networks’ GlobalProtect VPN and its endpoint agent, including flaws that could allow local privilege escalation and potentially give an attacker full administrative control over a device. The issues were responsibly reported to Palo Alto Networks and affect GlobalProtect versions used across enterprise environments.
Five Vulnerabilities Reported to Palo Alto Networks
Researcher Martin von Randow said the five vulnerabilities were originally submitted to Palo Alto Networks in early April 2026. Two of the flaws were eventually folded into CVE-2026-0251, described as a set of local privilege escalation vulnerabilities in the GlobalProtect application.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
One vulnerability involved an arbitrary file read issue that could allow a local, low-privileged user to escalate to NT AUTHORITY\SYSTEM on Windows and gain full administrative control of a device.
The National Vulnerability Database lists a CVSS 3.1 base score of 7.8 for CVE-2026-0251, reflecting the seriousness of local privilege escalation on a widely deployed VPN client.
The researcher also said his work uncovered a method to recover a user’s Active Directory password directly from an endpoint by abusing privileged GlobalProtect components. He said this could have implications for corporate identity infrastructure beyond local exploitation.
Two Flaws Reportedly Rejected, One Remains Unpatched
The disclosure also highlighted disagreements over the handling of some of the reported vulnerabilities. According to the researcher, two additional vulnerabilities were reportedly rejected as outside the scope of the vendor’s bug bounty programme, while a fifth issue remains unpatched and undisclosed as remediation continues.
The researcher said the initially patched CVE-2026-0251 was later withdrawn by Palo Alto Networks without notification to him and without credit in the accompanying advisory, prompting him to make the matter public.
The report states that more than 40 emails were exchanged with Palo Alto Networks’ Product Security Incident Response Team. The researcher described the process as involving prolonged periods without responses and shifting disclosure deadlines.
Four proof-of-concept exploits linked to the disclosed flaws have been made publicly available, while the fifth remains withheld pending an official fix from Palo Alto Networks.
GlobalProtect Flaws Raise Enterprise Security Concerns
Affected versions cited in the report span multiple GlobalProtect releases, including versions in the 6.0, 6.2 and 6.3 branches on Windows, macOS and Linux. The report states that Palo Alto has published patched builds for each, though the vendor has said the flaws covered by CVE-2026-0251 are not aware of active exploitation in the wild.
The vulnerabilities are significant because endpoint and VPN software can occupy privileged positions inside corporate networks. Such applications may connect directly with Active Directory and identity systems, making local privilege escalation and credential-recovery flaws particularly important for enterprise security teams.
The disclosure also points to broader concerns about vulnerability coordination between researchers and technology vendors. The researcher argued that technical intelligence can lose value when disclosure processes depend on slow communication, unclear handling procedures and limited coordination.