CVE-2026-0294

Prisma Access Agent: Local Privilege Escalation

Severity
Medium 6
CVSS 4.0
Exploited
Not listed
EPSS
0.001
2.3th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 13, 2026
Assigned by palo_alto

Description

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

Weakness: CWE-427

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported products (2)
  • Palo Alto Networks · Prisma Access Agent
  • Palo Alto Networks · Prisma Access Agent — vendor states not affected

Credit

Michael Garrison of State Farm Information Security

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Windows 24.0 through 26.2.2 Upgrade to 26.3 or later. Prisma Access Agent on macOS 24.0 through 26.2.2 Upgrade to 26.3 or later. Prisma Access Agent on Linux No action needed. Prisma Access Agent on iOS No action needed. Prisma Access Agent on Android No action needed. Prisma Access Agent on Chrome OS No action needed.

Something wrong here?