CVE-2026-0291: Palo Alto Networks Prisma Access Agent
Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
Affected products
- Palo Alto Networks Prisma Access Agent: before 26.2.2 (fixed in 26.2.2)
Published 2026-08-13. Last modified 2026-09-09.