CVE-2023-0006: Palo Alto Networks Globalprotect

Medium severity, CVSS 6.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.

Affected products

  • Palo Alto Networks Globalprotect: from 5.2.0, before 5.2.13 (fixed in 5.2.13); from 6.0.0, before 6.0.4 (fixed in 6.0.4); version 6.1.0 only

Published 2023-04-12. Last modified 2026-06-17.