CVE-2026-0247

Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

Severity
Medium 5.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
4.9th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto

Description

Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.

Weakness: CWE-306

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Prisma Access Agent

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution Prisma Access Agent (Endpoint DLP) 25.0 through 26.2 Upgrade to 26.2.1 or later.