CVE-2026-0305 MEDIUM

CVE-2026-0305: Prisma Access Agent: Information Disclosure Vulnerability on Linux

Vendor Palo Alto Networks
Product Prisma Access Agent
Weakness CWE-200 · Info exposure
Published September 10, 2026
Last update September 10, 2026

CVSS base score

4.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/V:D/RE:M/U:Amber

What the vulnerability does

01Description

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.

Key dates

02Disclosure timeline

September 10, 2026 CVE published

Related vulnerabilities

04Related CVE