CVE-2026-0306 MEDIUM

CVE-2026-0306: Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows

Vendor Palo Alto Networks
Product Prisma Access Agent
Weakness CWE-693
Published September 10, 2026
Last update September 10, 2026

CVSS base score

5.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

What the vulnerability does

01Description

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.

Key dates

02Disclosure timeline

September 10, 2026 CVE published