Executive brief
Palo Alto Networks Prisma Access Agent is a security client that enforces data loss prevention (DLP) policies to prevent sensitive data exfiltration. A vulnerability in the Windows version allows a local user to bypass these DLP controls and steal confidential information, though the Linux, macOS, iOS, Android, and Chrome OS versions are not affected.
Technical details
This is a protection mechanism failure (CWE-693) in the DLP enforcement logic of Prisma Access Agent on Windows. The vulnerability requires local access and low privileges to exploit; an authenticated local user can bypass the configured DLP policy enforcement controls without additional preconditions. An attacker can use this to exfiltrate sensitive data protected by the DLP policies. The issue affects Windows versions prior to 26.2; patched versions 26.2 and later are available and should be deployed.
Affected products
- Palo Alto Networks Prisma Access Agent < 26.2 on Windows
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fix available in version 26.2 and later