CVE-2026-0278

Summary

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.

The Prisma Access Agent on macOS is not affected.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksPrisma Access Agent24.0 < 26.2.1affected
Palo Alto NetworksPrisma Access AgentAllunaffected

Weaknesses

  • CWE-693: CWE-693 Protection Mechanism Failure

Workarounds

No known workarounds exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References