Junglewise Threat Intelligence

CVE-2026-0278: Palo Alto Networks Prisma Access Agent DLP bypass on Windows

CVE-2026-0278 · Severity: info · CVSS 5.8 · Published 2026-07-09

Technologies: Palo Alto Networks Prisma Access Agent. Vendors: Palo Alto Networks.

Executive brief

A vulnerability in the Windows version of Palo Alto Networks Prisma Access Agent allows local users to bypass Data Loss Prevention (DLP) controls. Prisma Access is a security tool used to protect corporate data and enforce security policies on remote devices. An exploit could allow an employee or someone with access to a company laptop to circumvent security rules and move sensitive data out of the organization without detection.

Technical details

The Prisma Access Agent for Windows contains multiple protection mechanism failures (CWE-693) within its Data Loss Prevention (DLP) component. A local attacker with low privileges can exploit these failures to bypass DLP policy enforcement, potentially leading to unauthorized data exfiltration or integrity violations. The vulnerability is specific to the Windows platform; the macOS agent is not affected. The issue is resolved in Prisma Access Agent version 26.2.1.

Affected products

  • Palo Alto Networks Prisma Access Agent 24.0 through 26.2 on Windows

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched: Fixed in version 26.2.1

References

Related threats