CVE-2026-0289

Prisma Browser: Inappropriate Implementation in Account Protection

Severity
Low 0.5
CVSS 4.0
Exploited
Not listed
EPSS
0.002
5.5th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 13, 2026
Assigned by palo_alto

Description

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

Weakness: CWE-522

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Browser SASE / SSE / Secure Web cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Prisma Browser

Credit

Palo Alto Networks thanks Thomas Villanueva for discovering and reporting this issue.

Vendor remediation

VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 150.49.4.125 or later.

Something wrong here?