Impact
A local user can bypass the Data Loss Prevention rules enforced by the Prisma Access Agent on Windows. The flaw allows a user with normal local privileges to send protected data outside the corporate network, undermining confidentiality. The weakness is classified as CWE‑693: Event or Data Manipulation without proper authorization or validation.
Affected Systems
Palo Alto Networks Prisma Access Agent for Windows versions 24.0 through 26.2 are affected. The agent on macOS, Linux, iOS, Android, and Chrome OS is not impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 5.8, indicating medium severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. An attacker must have local access to the endpoint to exploit this bypass. No remote exploitation or privilege escalation is required or mentioned in the report, so the attack surface is limited to insider or compromised local users.
OpenCVE Enrichment