CVE-2026-0293
Received Received - Intake

Local Privilege Escalation in Palo Alto Prisma Access Agent

Vulnerability report for CVE-2026-0293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Palo Alto Networks, Inc.

Description

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
palo_alto_networks prisma_access_agent From 24.0 (inc) to 26.2.2 (inc)
palo_alto_networks prisma_access_agent 26.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a local attacker with administrator privileges on Windows to bypass anti-tamper protection in Palo Alto Networks Prisma Access Agent. This enables unauthorized access to protected processes and files. The issue does not affect other operating systems like Linux, macOS, iOS, Android, or Chrome OS.

Detection Guidance

Detection primarily involves checking the installed version of the Prisma Access Agent on Windows systems. Compare the version against the affected range (24.0 through 26.2.2). Use the following command in PowerShell or Command Prompt: 'wmic product where "name like 'Palo Alto Networks Prisma Access Agent'" get version'.

Impact Analysis

If you are a Windows user running affected Prisma Access Agent versions (24.0 to 26.2.2), an attacker with admin access could bypass security protections and access sensitive files or processes. This could lead to data theft, system compromise, or further attacks on your system.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to protected processes and files on Windows systems. Bypassing anti-tamper protection may lead to data breaches or unauthorized modifications, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Upgrade the Prisma Access Agent on all Windows systems to version 26.3 or later immediately. No workarounds are available, so patching is the only mitigation. Verify the upgrade by re-running the version check command after installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart