Description
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files.

The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Published: 2026-08-13
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker who already holds administrator privileges on a Windows system can bypass the Prisma Access Agent’s anti‑tamper protection, allowing that attacker to access processes and files that are normally protected by the agent. The flaw is a classic example of improper protection of essential data (CWE‑693).

Affected Systems

The vulnerability affects Palo Alto Networks Prisma Access Agent on Windows versions 24.0 through 26.2.2. Versions on macOS, Linux, iOS, Android, and Chrome OS are not impacted.

Risk and Exploitability

The CVSS score of 5.6 indicates a moderate severity. Because the exploit requires local administrator rights and there are no public exploits documented, the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalogue. The attack vector is local, so only users who can already gain administrative access to a Windows machine can leverage this weakness to obtain further unauthorized access to protected processes or files.

Generated by OpenCVE AI on August 13, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Windows installations of the Prisma Access Agent to version 26.3 or later.
  • Apply the same upgrade to any older unsupported versions to reach a supported fixed release.
  • Restrict local administrator privileges to only users who need them, and enable audit logging to detect suspicious activity.

Generated by OpenCVE AI on August 13, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Title Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Access Agent
Weaknesses CWE-693
CPEs cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:Windows:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Access Agent
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Access Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-08-13T01:51:07.249Z

Reserved: 2025-11-03T20:44:51.366Z

Link: CVE-2026-0293

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T03:16:44.160

Modified: 2026-08-13T03:16:44.160

Link: CVE-2026-0293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:00:08Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure