Description
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.

The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
Published: 2026-08-13
Score: 1.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper link resolution before file access flaw allows a local low‑privileged user to delete system files in a limited scope, disabling the Prisma Access Agent. The vulnerability manifests as a filesystem restriction weakness (CWE‑59) that can compromise the availability of the agent and potentially affect system integrity if critical system files are removed.

Affected Systems

The affected product is Palo Alto Networks Prisma Access Agent on Linux platforms. Vulnerable releases span from 25.7 through 26.2.1. The macOS, Windows, iOS, Android, and Chrome OS binaries are not impacted.

Risk and Exploitability

The CVSS score is 1.1, indicating a very low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local access with low privileges; the user must be able to run processes on the Linux host. Exploitation is straightforward once the user can execute commands, making the risk primarily tied to the presence of unprivileged local accounts.

Generated by OpenCVE AI on August 13, 2026 at 03:20 UTC.

Remediation

Vendor Workaround

No known workarounds or mitigations exist for this issue.


OpenCVE Recommended Actions

  • Upgrade the Prisma Access Agent on Linux to version 26.2.2 or higher
  • Ensure that local low‑privileged users have read‑only access to the agent’s installation directories and system files, modifying ownership or permissions as needed
  • Deploy monitoring to detect unexpected deletions of agent binaries or restarts, and consider using SELinux/AppArmor profiles to further restrict file system access

Generated by OpenCVE AI on August 13, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
Title Prisma Access Agent: Authenticated Limited File Deletion on Linux
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Access Agent
Weaknesses CWE-59
CPEs cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:Linux:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Access Agent
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Access Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T01:47:59.370Z

Reserved: 2025-11-03T20:44:48.974Z

Link: CVE-2026-0291

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:43.800

Modified: 2026-08-13T03:16:43.800

Link: CVE-2026-0291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:30:04Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')