CVE-2026-0291

Prisma Access Agent: Authenticated Limited File Deletion on Linux

Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
2.2th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 13, 2026
Assigned by palo_alto

Description

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

Weakness: CWE-59

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported products (2)
  • Palo Alto Networks · Prisma Access Agent
  • Palo Alto Networks · Prisma Access Agent — vendor states not affected

Credit

an internal reporter

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Linux 25.7 through 26.2.1 Upgrade to 26.2.2 or later. Prisma Access Agent on macOS No action needed. Prisma Access Agent on Windows No action needed. Prisma Access Agent on iOS No action needed. Prisma Access Agent on Android No action needed. Prisma Access Agent on Chrome OS No action needed.

Something wrong here?