CVEFinder.io

CVE-2026-0267

๐Ÿ”ถ medium
๐Ÿ” Scan for this CVE
Summary

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.

CVSS Score
5.5
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2026-06-10
First Seen: 2026-06-11
๐Ÿ“Š Relative Risk Intelligence

This CVE is Lower Risk - more severe than 31.7% of all 344,912 vulnerabilities in our database.

#235,563
Below average severity
Severity Percentile
๐ŸŽฏ CISA SSVC Assessment Updated: Jun 11, 2026
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
NO
Requires human interaction
๐Ÿ’ฅ Technical Impact
Partial
Limited system impact
๐Ÿ† Discovered By
Palo Alto Networks thanks one of our customers for discovering and reporting this issue.
SSVC data provided by CISA
Last Modified 2026-07-23
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Vector 4.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 4

๐Ÿ”— References 2

๐Ÿ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-0249 ๐Ÿ”ถ medium 6.5 0.1 Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtectโ„ข app enables an attac... 2026-05-13
CVE-2026-0250 โš ๏ธ high 8.1 0.4 A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtectโ„ข app that enables a man in the middle a... 2026-05-13
CVE-2026-0251 โš ๏ธ high 7.8 0.2 Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtectโ„ข app allow a local user to... 2026-05-13
CVE-2025-4232 โš ๏ธ high 8.8 0.1 2025-06-13
CVE-2025-4227 โ„น๏ธ low 3.5 0.0 An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g... 2025-06-13
CVE-2025-0135 โ„น๏ธ low 3.3 0.0 An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtectโ„ข App on macOS devices enables ... 2025-05-14
These CVEs affect the same products