CVE-2026-0294 MEDIUM

CVE-2026-0294: Prisma Access Agent: Local Privilege Escalation

Vendor Palo Alto Networks
Product Prisma Access Agent
Weakness CWE-427
Published August 13, 2026
Last update August 13, 2026

CVSS base score

6.0/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:C/RE:M/U:Amber

What the vulnerability does

01Description

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated