Executive brief
A security flaw in the Linux version of the Prisma Access Agent allows a local user to bypass VPN security controls. This could allow network traffic to be routed outside of the secure encrypted tunnel, potentially exposing sensitive data to the local network or internet. This issue only affects Linux users and does not impact Windows, macOS, or mobile versions of the software.
Technical details
A security control bypass vulnerability exists in Prisma Access Agent for Linux due to improper protection of alternate paths (CWE-424). A local authenticated attacker with low privileges can exploit this flaw to route network traffic outside of the established VPN tunnel. This bypasses the intended security enforcement that ensures all traffic is encapsulated within the secure tunnel. The vulnerability is specific to the Linux agent and does not affect other operating systems. The issue is resolved in Prisma Access Agent for Linux version 26.2.1.
Affected products
- Palo Alto Networks Prisma Access Agent Linux versions < 26.2.1
Timeline
- 2026-06-10: disclosed: Initial publication of the advisory by Palo Alto Networks.
- 2026-06-10: patched: Fix released in version 26.2.1.