Executive brief
A security vulnerability in the Palo Alto Networks Prisma Access Agent for Linux could allow a person with standard user access to gain full administrative control over the device. This agent is typically used to provide secure remote access to corporate resources. If exploited, an attacker who already has a foothold on a Linux machine could bypass security restrictions to access sensitive data or disrupt system operations.
Technical details
A local privilege escalation vulnerability exists in the Palo Alto Networks Prisma Access Agent for Linux due to incorrect permission assignment for a critical resource (CWE-732). The flaw allows a local authenticated user with low privileges to execute arbitrary code with elevated (root) privileges. The vulnerability is specific to the Linux version of the agent and does not affect Windows, macOS, iOS, Android, or ChromeOS versions. Attackers require local shell access but no special configuration or user interaction to trigger the exploit. Palo Alto Networks has addressed this issue in Prisma Access Agent version 26.2.1 for Linux.
Affected products
- Palo Alto Networks Prisma Access Agent < 26.2.1 on Linux
Timeline
- 2026-06-10: disclosed: Initial publication of the advisory
- 2026-06-10: patched: Fixed in version 26.2.1