CVE-2026-0305

Summary

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials.

The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksPrisma Access Agent24.0 < 26.2affected
Palo Alto NetworksPrisma Access AgentAll < 6.3.3-h15unaffected

Weaknesses

  • CWE-200: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Workarounds

No known workarounds or mitigations exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References