CVE-2026-0294

Summary

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.

The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksPrisma Access Agent0 < 26.3affected
Palo Alto NetworksPrisma Access AgentAllunaffected

Weaknesses

  • CWE-427: CWE-427: Uncontrolled Search Path Element

Workarounds

No known workarounds exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References