CVE-2020-1989: Palo Alto Networks Globalprotect

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global Protect Agent for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1.

Affected products

  • Palo Alto Networks Globalprotect: from 5.0, before 5.0.8 (fixed in 5.0.8); from 5.1, before 5.1.1 (fixed in 5.1.1)

Published 2020-04-08. Last modified 2026-06-17.