Executive brief
A vulnerability in the Windows version of Palo Alto Networks Prisma Access Agent allows local users to bypass Data Loss Prevention (DLP) controls. Prisma Access is a security tool used to protect corporate data and enforce security policies on remote devices. An exploit could allow an employee or someone with access to a company laptop to circumvent security rules and move sensitive data out of the organization without detection.
Technical details
The Prisma Access Agent for Windows contains multiple protection mechanism failures (CWE-693) within its Data Loss Prevention (DLP) component. A local attacker with low privileges can exploit these failures to bypass DLP policy enforcement, potentially leading to unauthorized data exfiltration or integrity violations. The vulnerability is specific to the Windows platform; the macOS agent is not affected. The issue is resolved in Prisma Access Agent version 26.2.1.
Affected products
- Palo Alto Networks Prisma Access Agent 24.0 through 26.2 on Windows
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched: Fixed in version 26.2.1