Executive brief
Prisma Access Agent, used to secure remote access on Linux systems, contains a vulnerability that allows an authenticated local attacker to read sensitive configuration data and stored credentials from the system. This could expose VPN credentials and configuration details that an attacker could use for lateral movement or unauthorized access to protected networks.
Technical details
This is an information disclosure vulnerability (CWE-200) in Prisma Access Agent on Linux that allows a local user with low privileges to access sensitive configuration data and stored credentials. The vulnerability requires local access with low-level privileges and no user interaction; the attack complexity is low. An authenticated local attacker can read sensitive information including VPN credentials and configuration details. The vulnerability affects versions 24.0 through 26.2.2 on Linux; a fix is available in version 26.3 and later. Other platforms (macOS, Windows, iOS, Android, Chrome OS) are unaffected.
Affected products
- Palo Alto Networks Prisma Access Agent 24.0 through 26.2.2 on Linux
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fix available in version 26.3 and later