CyberSecurityNews

Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect PAN


A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint agent used across thousands of enterprise networks worldwide.

The disclosure, published through a dedicated research site, has reignited debate over how vendors handle vulnerability reports even when researchers follow coordinated disclosure norms.

According to the researcher Martijn van Ramesdonk, the five issues were originally submitted to Palo Alto Networks in early April 2026, and two of them were eventually folded into CVE-2026-0251, a set of local privilege escalation flaws in the GlobalProtect app.

Palo Alto’s own advisory confirms that the bugs allow a local, low-privileged user to escalate to NT AUTHORITYSYSTEM on Windows and to root on macOS and Linux, giving an attacker who already has a foothold on an endpoint the ability to run arbitrary commands with full administrative control.

The National Vulnerability Database lists a CVSS 3.1 base score of 7.8, reflecting the seriousness of local privilege escalation on a widely deployed VPN client.

Beyond privilege escalation, the researcher says his work also uncovered a method to recover a user’s Active Directory password directly from the endpoint by abusing privileged GlobalProtect components, a finding with far more direct implications for corporate identity infrastructure than a typical local exploit.

What makes this case notable is not just the technical severity but the researcher’s account of the disclosure journey itself. He says the two vulnerabilities behind CVE-2026-0251 were initially patched by Palo Alto Networks without any notification to him and without credit in the accompanying advisory, prompting him to push back publicly.

Two further vulnerabilities were reportedly deemed out of scope for the vendor’s bug bounty program, while a fifth remains unpatched and undisclosed while remediation work continues.

The researcher describes more than 40 emails exchanged with Palo Alto’s Product Security Incident Response Team and multiple missed or shifting disclosure deadlines stretched across several months, a process he characterizes as symptomatic of a broken coordination model rather than a technical failure.

Four proof-of-concept exploits tied to the disclosed flaws are now publicly available, while the fifth is being withheld pending an official fix from Palo Alto Networks. Affected versions span multiple GlobalProtect 6.0, 6.2, and 6.3 branches on Windows, macOS, and Linux, and Palo Alto has published patched builds for each, though the vendor has stated it is not aware of active exploitation in the wild.

Endpoint and VPN software occupies a privileged position inside enterprise networks, often bridging directly into Active Directory and identity systems, which makes local privilege escalation and credential-recovery bugs in these products disproportionately dangerous compared to flaws in less trusted applications.

The researcher’s broader point, that artificial intelligence is accelerating vulnerability discovery faster than vendors can validate, patch, and credit findings, points to a looming bottleneck: finding bugs is getting easier, but responsible, well-coordinated disclosure still depends on human judgment, mature internal processes, and accountability that no automation can substitute.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link