CVE-2026-0278
Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
Severity
Medium 5.8
CVSS 4.0
Exploited
Not listed
EPSS
0.001
1.2th percentile
Discovered by
Third party
Published by the vendor
Published
Jul 9, 2026
Assigned by palo_alto
Description
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
Weakness: CWE-693
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · Prisma Access Agent
- Palo Alto Networks · Prisma Access Agent
Credit
Daniel Cuthbert and Vladislav Ovitchinikov from Banco Santander
Vendor remediation
Version Minor Version Suggested Solution Prisma Access Agent on Windows 24.0 through 26.2 Upgrade to 26.2.1 or later. Prisma Access Agent on macOS No action needed.