CVE-2026-0268
Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
Description
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
Weakness: CWE-424
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · Prisma Access Agent
- Palo Alto Networks · Prisma Access Agent
Credit
our internal security research teams
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Linux 25.7 through 26.2.0 Upgrade to 26.2.1 or later. Prisma Access Agent All on Windows No action needed. Prisma Access Agent All on macOS No action needed. Prisma Access Agent All on iOS No action needed. Prisma Access Agent All on Android No action needed. Prisma Access Agent All on Chrome OS No action needed.