Impact
An authentication bypass in the network driver of Palo Alto Networks Prisma Access Agent on Windows can allow a local administrator to sidestep security inspection, enabling them to inject arbitrary data into or intercept traffic passing through the agent. The flaw is tied to missing authorization controls (CWE-290) and permits the attacker to manipulate network traffic without needing external network access. The impact is limited to processes and data that travel through the affected Windows agent and does not grant additional system privileges beyond those already possessed by the local administrator.
Affected Systems
The vulnerability affects the Windows edition of the Prisma Access Agent, specifically versions 24.0 through 26.2.2 inclusive. Other supported operating systems—Linux, macOS, iOS, Android, and Chrome OS—are not impacted.
Risk and Exploitability
With a CVSS score of 2.1 the vulnerability is in the low severity range, and no EPSS or KEV status indicates low likelihood of exploitation. The attack vector requires local administrator privileges on the host running the vulnerable agent; there is no requirement for external network access. Although the severity is low, an adversary who gains local admin rights could bypass security inspection and manipulate traffic, potentially undermining confidentiality and integrity of communications that rely on the agent. The absence of a known workaround underscores the importance of applying the vendor’s recommended upgrade.
OpenCVE Enrichment