Junglewise Threat Intelligence

CVE-2026-0247: Palo Alto Networks Prisma Access Agent authorization bypass in Endpoint DLP

CVE-2026-0247 · Severity: high · CVSS 7.8 · Published 2026-05-13

Executive brief

Palo Alto Networks Prisma Access Agent is a security tool used to protect corporate data on employee laptops and workstations. A security flaw in its Data Loss Prevention (DLP) component allows a person with local access to the computer to bypass security checks and perform actions they shouldn't be allowed to do. This could lead to unauthorized access to sensitive information or the disruption of security controls on the device.

Technical details

Multiple authorization bypass vulnerabilities exist in the Endpoint DLP component of Palo Alto Networks Prisma Access Agent. The root cause is identified as a failure to perform authentication for critical functions (CWE-306). A local attacker with low privileges on a Windows or macOS system where Endpoint DLP is enabled can exploit these flaws to bypass authentication controls. Successful exploitation allows the attacker to execute privileged operations, potentially leading to a full compromise of the agent's integrity and confidentiality. The issue is resolved in Prisma Access Agent version 26.2.1.

Affected products

  • Palo Alto Networks Prisma Access Agent (Endpoint DLP) 25.0 through 26.2 (prior to 26.2.1)

Timeline

  • 2026-05-13: disclosed: Initial internal discovery and publication by Palo Alto Networks
  • 2026-05-13: advisory
  • 2026-05-13: patched: Fixed in version 26.2.1

References

Related threats