Description
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic.

The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Published: 2026-08-13
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass in the network driver of Palo Alto Networks Prisma Access Agent on Windows can allow a local administrator to sidestep security inspection, enabling them to inject arbitrary data into or intercept traffic passing through the agent. The flaw is tied to missing authorization controls (CWE-290) and permits the attacker to manipulate network traffic without needing external network access. The impact is limited to processes and data that travel through the affected Windows agent and does not grant additional system privileges beyond those already possessed by the local administrator.

Affected Systems

The vulnerability affects the Windows edition of the Prisma Access Agent, specifically versions 24.0 through 26.2.2 inclusive. Other supported operating systems—Linux, macOS, iOS, Android, and Chrome OS—are not impacted.

Risk and Exploitability

With a CVSS score of 2.1 the vulnerability is in the low severity range, and no EPSS or KEV status indicates low likelihood of exploitation. The attack vector requires local administrator privileges on the host running the vulnerable agent; there is no requirement for external network access. Although the severity is low, an adversary who gains local admin rights could bypass security inspection and manipulate traffic, potentially undermining confidentiality and integrity of communications that rely on the agent. The absence of a known workaround underscores the importance of applying the vendor’s recommended upgrade.

Generated by OpenCVE AI on August 13, 2026 at 03:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Prisma Access Agent on Windows to version 26.3 or later to eliminate the vulnerability.
  • Revoke or restrict local administrator privileges on systems that run the agent to prevent an attacker from exploiting the flaw.
  • Implement network traffic monitoring to detect anomalous injection or interception that could indicate a residual or opportunistic bypass attempt.

Generated by OpenCVE AI on August 13, 2026 at 03:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Title Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Access Agent
Weaknesses CWE-290
CPEs cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:Windows:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Access Agent
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:L/E:U/AU:N/R:A/V:C/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Access Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T01:49:19.448Z

Reserved: 2025-11-03T20:44:49.864Z

Link: CVE-2026-0292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:43.983

Modified: 2026-08-13T03:16:43.983

Link: CVE-2026-0292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:30:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing