Impact
The flaw originates from a security misconfiguration in the Data Loss Prevention (DLP) component of the Prisma Access Agent on Windows, allowing a local user to bypass established DLP policies. This bypass can lead to the unintended disclosure or improper handling of protected data, compromising the confidentiality of sensitive information. Classified as CWE‑693, the weakness represents improper handling of security controls and does not provide code execution paths; it solely relies on the ability of the attacker to alter or circumvent DLP settings within the agent.
Affected Systems
Palo Alto Networks Prisma Access Agent on Windows versions 24.0 through 26.2 is affected. The MacOS variant is not impacted. Any system running the affected Windows build with the DLP component enabled is at risk.
Risk and Exploitability
The CVSS base score of 5.8 classifies the issue as moderate severity, and the EPSS score of <1% indicates a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a local user who has sufficient privileges to modify the agent’s configuration or disable DLP policies. Based on the description, this is inferred that local users can exercise the bypass, potentially exfiltrating sensitive data. The overall risk depends on the presence and sensitivity of data processed by the affected systems and the privileges granted to local users.
OpenCVE Enrichment