Executive brief
A security flaw in the Palo Alto Networks Prisma Access Agent allows a standard user on a computer to gain full administrative control. The Prisma Access Agent is software used to securely connect remote employees to corporate networks. If exploited, an attacker who already has basic access to a laptop or workstation could take over the entire system, access sensitive files, and install malicious software.
Technical details
A vulnerability classified as Missing Authorization (CWE-862) exists in the privilege management mechanism of the Palo Alto Networks Prisma Access Agent. A locally authenticated non-administrative user can exploit this flaw to escalate their privileges to 'root' on macOS and Linux or 'NT AUTHORITY\SYSTEM' on Windows. The attack requires low privileges and no user interaction. Successful exploitation allows for arbitrary code execution and unauthorized access to sensitive system information. The issue is fixed in Prisma Access Agent version 26.2.1; mobile platforms (iOS, Android, ChromeOS) are not affected.
Affected products
- Palo Alto Networks Prisma Access Agent < 26.2.1 (Linux, macOS, Windows)
Timeline
- 2026-05-13: disclosed: Initial publication by Palo Alto Networks
- 2026-05-13: advisory
- 2026-06-04: patched: Estimated patch availability for affected platforms