CVE-2026-0293
Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
Description
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Weakness: CWE-693
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (2)
- Palo Alto Networks · Prisma Access Agent
- Palo Alto Networks · Prisma Access Agent — vendor states not affected
Credit
Palo Alto Networks thanks Daniel Cuthbert and Vladislav Ovitchinikov from Banco Santander for discovering and reporting this issue.
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Windows 24.0 through 26.2.2 Upgrade to 26.3 or later. Prisma Access Agent on macOS No action needed. Prisma Access Agent on Linux No action needed. Prisma Access Agent on iOS No action needed. Prisma Access Agent on Android No action needed. Prisma Access Agent on Chrome OS No action needed. All older unsupported versions Upgrade to a supported fixed version.