Impact
An improper link resolution before file access flaw allows a local low‑privileged user to delete system files in a limited scope, disabling the Prisma Access Agent. The vulnerability manifests as a filesystem restriction weakness (CWE‑59) that can compromise the availability of the agent and potentially affect system integrity if critical system files are removed.
Affected Systems
The affected product is Palo Alto Networks Prisma Access Agent on Linux platforms. Vulnerable releases span from 25.7 through 26.2.1. The macOS, Windows, iOS, Android, and Chrome OS binaries are not impacted.
Risk and Exploitability
The CVSS score is 1.1, indicating a very low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local access with low privileges; the user must be able to run processes on the Linux host. Exploitation is straightforward once the user can execute commands, making the risk primarily tied to the presence of unprivileged local accounts.
OpenCVE Enrichment