CVE-2026-0291: Palo Alto Networks Prisma Access Agent

Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

Affected products

Published 2026-08-13. Last modified 2026-09-09.