Description
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data.



This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Published: 2026-09-10
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local user can bypass the Data Loss Prevention rules enforced by the Prisma Access Agent on Windows. The flaw allows a user with normal local privileges to send protected data outside the corporate network, undermining confidentiality. The weakness is classified as CWE‑693: Event or Data Manipulation without proper authorization or validation.

Affected Systems

Palo Alto Networks Prisma Access Agent for Windows versions 24.0 through 26.2 are affected. The agent on macOS, Linux, iOS, Android, and Chrome OS is not impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 5.8, indicating medium severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. An attacker must have local access to the endpoint to exploit this bypass. No remote exploitation or privilege escalation is required or mentioned in the report, so the attack surface is limited to insider or compromised local users.

Generated by OpenCVE AI on September 10, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Prisma Access Agent on Windows to version 26.2 or later.
  • Verify that the updated agent enforces DLP policy controls against data exfiltration.
  • Monitor endpoint activity for signs of abnormal data transfer and review logs for DLP rule violations.

Generated by OpenCVE AI on September 10, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Title Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Access Agent
Weaknesses CWE-693
CPEs cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:android:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:chromeos:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:ios:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:linux:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:macos:*:*:*:*:*
cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:windows:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Access Agent
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Access Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-09-10T05:55:23.322Z

Reserved: 2025-11-03T20:45:04.920Z

Link: CVE-2026-0306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T06:17:03.007

Modified: 2026-09-10T06:17:03.007

Link: CVE-2026-0306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:30:07Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure