← All Advisories

Palo Alto Networks Prisma Access Agent's Uncontrolled Search Path Allows a Local Attacker to Place a Malicious Library Where the Agent Will Load It

Last refreshed2026-09-27

Status: EXPLOITED  |  Advisory ID: CVE-2026-0294

Key Details

CVECVE-2026-0294
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPalo Alto Networks Prisma Access Agent
Exploitation statusPalo Alto Networks is not aware of any malicious exploitation of this issue.
Classified asCWE-427 (Uncontrolled Search Path Element)
Exploitation prediction (EPSS)0.11% probability of exploitation in the next 30 days (1% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksPrisma Access Agent
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.

The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

What to Do

Prisma Access Agent on Windows and macOS (24.0 through 26.2.2): upgrade to 26.3 or later. Prisma Access Agent on Linux, iOS, Android, and Chrome OS: no action needed. Workarounds and Mitigations: no known workarounds exist for this issue.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0294
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0294
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0294