Description
An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.
Published: 2026-08-13
Score: 0.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Account Protection feature of Palo Alto Networks Prisma Browser and permits a local attacker to read sensitive data that should be protected. Because the flaw involves insecure handling of stored credentials (CWE‑522), the attacker could retrieve confidential login information or other protected values. This leads to a disclosure of sensitive information to a user with local access to the system.

Affected Systems

Palo Alto Networks Prisma Browser versions prior to 148.18.4.217 are affected. The issue is present in all releases that use the legacy Account Protection implementation, so any installation lacking the 148.18.4.217 update is vulnerable.

Risk and Exploitability

The CVSS score of 0.5 indicates a minimal severity under the current assessment, and no EPSS data is available, suggesting low known exploitation likelihood. The flaw can be exploited only by an attacker who already has local access to the device; there is no remote exploitation vector. The vulnerability is not listed in the CISA KEV catalog, further indicating that it has not yet been widely exploited in the wild.

Generated by OpenCVE AI on August 13, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Prisma Browser to version 148.18.4.217 or newer.
  • If the update cannot be applied immediately, restrict local user accounts from accessing Account Protection data until the patch is installed.
  • Continue monitoring local account activity for signs of unauthorized credential exposure.

Generated by OpenCVE AI on August 13, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.
Title Prisma Browser: Sensitive Information Disclosure Vulnerability
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Browser
Weaknesses CWE-522
CPEs cpe:2.3:a:palo_alto_networks:prisma_browser:*:*:*:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Browser
References
Metrics cvssV4_0

{'score': 0.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Browser
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T01:45:39.372Z

Reserved: 2025-11-03T20:44:48.137Z

Link: CVE-2026-0290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:43.647

Modified: 2026-08-13T03:16:43.647

Link: CVE-2026-0290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:30:04Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials