CVE-2026-0247
Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities
Severity
Medium 5.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
4.9th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto
Description
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.
Weakness: CWE-306
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Prisma Access Agent
Credit
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
Vendor remediation
Version Minor Version Suggested Solution Prisma Access Agent (Endpoint DLP) 25.0 through 26.2 Upgrade to 26.2.1 or later.