Description
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.



The Prisma Access Agent on macOS is not affected.
Published: 2026-07-09
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw originates from a security misconfiguration in the Data Loss Prevention (DLP) component of the Prisma Access Agent on Windows, allowing a local user to bypass established DLP policies. This bypass can lead to the unintended disclosure or improper handling of protected data, compromising the confidentiality of sensitive information. Classified as CWE‑693, the weakness represents improper handling of security controls and does not provide code execution paths; it solely relies on the ability of the attacker to alter or circumvent DLP settings within the agent.

Affected Systems

Palo Alto Networks Prisma Access Agent on Windows versions 24.0 through 26.2 is affected. The MacOS variant is not impacted. Any system running the affected Windows build with the DLP component enabled is at risk.

Risk and Exploitability

The CVSS base score of 5.8 classifies the issue as moderate severity, and the EPSS score of <1% indicates a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a local user who has sufficient privileges to modify the agent’s configuration or disable DLP policies. Based on the description, this is inferred that local users can exercise the bypass, potentially exfiltrating sensitive data. The overall risk depends on the presence and sensitivity of data processed by the affected systems and the privileges granted to local users.

Generated by OpenCVE AI on July 29, 2026 at 11:59 UTC.

Remediation

Vendor Workaround

No known workarounds exist for this issue.


OpenCVE Recommended Actions

  • Upgrade the Windows Prisma Access Agent to version 26.2.1 or later.
  • Verify that the DLP component is enabled and all relevant policies are active after the update.
  • Restrict local user privileges to the minimum necessary, preventing unauthorized modification or disabling of DLP settings.

Generated by OpenCVE AI on July 29, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
Title Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Access Agent
Weaknesses CWE-693
CPEs cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:windows:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access_agent:all:*:macos:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Access Agent
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:C/RE:H/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Access Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-07-11T03:55:14.977Z

Reserved: 2025-11-03T20:44:37.292Z

Link: CVE-2026-0278

cve-icon Vulnrichment

Updated: 2026-07-10T14:19:30.710Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure