Executive brief
Palo Alto Networks Prisma Access Agent, a tool used to securely connect remote users to corporate resources, contains a security flaw on Windows and macOS. A person with local access to a computer could exploit this vulnerability to view sensitive configuration settings and user credentials. This could lead to unauthorized access to corporate data or further compromise of the user's account.
Technical details
Multiple information disclosure vulnerabilities (CWE-200) exist in the Palo Alto Networks Prisma Access Agent for Windows and macOS. The flaw allows a local authenticated user with low privileges to access sensitive configuration data and stored credentials. The vulnerability is specific to the Windows and macOS versions of the agent; Linux, ChromeOS, Android, and iOS versions are not affected. Attackers can leverage this to gain unauthorized access to sensitive environment details or user authentication material. The issue is resolved in Prisma Access Agent version 26.2.1.
Affected products
- Palo Alto Networks Prisma Access Agent 24.0 through 26.2 (Windows and macOS)
Timeline
- 2026-05-13: disclosed: Initial internal discovery and publication by Palo Alto Networks
- 2026-05-13: patched: Fixed in version 26.2.1