CVE-2026-0267
๐ถ mediumSummary
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
CVSS Score
5.5
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2026-06-10
First Seen: 2026-06-11
๐ Relative Risk Intelligence
This CVE is Lower Risk - more severe than 31.7% of all 344,912 vulnerabilities in our database.
#235,563
Below average severity
Severity Percentile
๐ฏ CISA SSVC Assessment Updated: Jun 11, 2026
๐ Exploitation Status
None
No known exploits
โ๏ธ Automatable
NO
Requires human interaction
๐ฅ Technical Impact
Partial
Limited system impact
๐ Discovered By
Palo Alto Networks thanks one of our customers for discovering and reporting this issue.
SSVC data provided by
CISA
Last Modified
2026-07-23
Source
NVD ๐
CVSS Vector 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Vector 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
CWE IDs (Weakness Types)