Impact
An information‑disclosure flaw exists in the Palo Alto Networks Prisma Access Agent running on Linux. The vulnerability allows a local user to read sensitive configuration files and credentials that are normally protected, resulting in unauthorized disclosure of confidential data. This weakness is classified as CWE‑200, indicating improper information exposure.
Affected Systems
Affected is the Palo Alto Networks Prisma Access Agent on Linux versions 25.7 through 26.2.2. The agent running on macOS, Windows, iOS, Android, and Chrome OS is not affected. Only Linux installations need to be audited and updated.
Risk and Exploitability
The CVSS score of 4.3 reflect a moderate severity due to the local attack requirement. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local user access and the attacker can read configuration data, but cannot gain remote code execution or broader system compromise. The risk is moderate, and systems should apply the fix to mitigate potential data leakage.
OpenCVE Enrichment