Palo Alto NetworksCVE-2026-0292
Palo Alto Networks Prisma Access Agent: authentication bypass
Low2.1CVE-2026-0292 · Published Aug 13, 2026 · updated Sep 9, 2026
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Prisma Access Agent Product | < 26.3 | 26.3 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-290
More Palo Alto Networks advisories
All Palo Alto Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 13 | Palo Alto Networks Cloud NGFW: information disclosure | Low1.7 | 11.1.16-h1+2 more |
| Aug 13 | Palo Alto Networks GlobalProtect App: buffer overflow | Medium5.2 | 6.3.3-h15+4 more |
| Aug 13 | Palo Alto Networks GlobalProtect App: improper input validation | Medium5.2 | 6.3.3-h14+2 more |
| Aug 13 | Palo Alto Networks GlobalProtect App: privilege escalation | Medium5.9 | 6.3.3-h15+3 more |
| Aug 13 | Palo Alto Networks Prisma: local attacker could bypass the anti-tamper... | Medium5.6 | 26.3 |
| Aug 13 | Palo Alto Networks Prisma Access Agent: privilege escalation | Medium6.0 | 26.3 |