Description
A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.
Published: 2026-08-13
Score: 0.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Palo Alto Networks Prisma Browser’s Account Protection feature allows a user to bypass the intended security controls, potentially granting unauthorized account access. This flaw falls under CWE‑522, indicating insufficient protection of sensitive information. Because the bypass can be achieved without triggering additional authentication or authorization checks, an attacker may gain privileged access to the browser session or underlying system.

Affected Systems

Affected are installations of Prisma Browser with versions earlier than 150.49.4.125. All users running the default configuration on these versions are susceptible until they apply the vendor‑supplied upgrade.

Risk and Exploitability

The CVSS score of 0.5 indicates a low severity risk for individual infections, and the EPSS score is not available; KEV does not list this vulnerability. Nonetheless, the flaw requires an attacker to be in a position to interact with the browser and leverage the bypass, making it a local or user‑initiated attack vector. Given the low scoring metrics, the likelihood of widespread exploitation is small, but it remains a potential internal threat especially in environments where account protection is relied upon for secure access.

Generated by OpenCVE AI on August 13, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Prisma Browser to version 150.49.4.125 or later.
  • Re‑enable or verify that the Account Protection feature is correctly configured after the upgrade.
  • Continuously monitor authentication logs for signs of unauthorized access and apply future patches promptly.

Generated by OpenCVE AI on August 13, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.
Title Prisma Browser: Inappropriate Implementation in Account Protection
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Browser
Weaknesses CWE-522
CPEs cpe:2.3:a:palo_alto_networks:prisma_browser:*:*:*:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Browser
References
Metrics cvssV4_0

{'score': 0.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Browser
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T01:44:29.032Z

Reserved: 2025-11-03T20:44:47.234Z

Link: CVE-2026-0289

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:43.107

Modified: 2026-08-13T03:16:43.107

Link: CVE-2026-0289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:00:08Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials