Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

MonitorCVSS 6.1CVE-2026-0292Aug 12, 2026
Palo Alto NetworksTransportation
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma Access Agent on Windows allows a local administrator to bypass security inspection and inject or intercept arbitrary network traffic. The vulnerability affects Windows versions below 26.3. Linux, macOS, iOS, Android, and Chrome OS versions are unaffected.

What this means
What could happen
A local administrator on a Windows machine running Prisma Access Agent could bypass network security inspection, allowing them to inject malicious traffic or intercept sensitive data that should be protected by the agent.
Who's at risk
Transportation sector organizations using Palo Alto Networks Prisma Access Agent on Windows endpoints are affected. This includes remote workers, mobile workforce, and branch offices that rely on the agent for secure network access. Linux, macOS, iOS, Android, and Chrome OS endpoints are not vulnerable.
How it could be exploited
An attacker with local administrator access to a Windows machine can exploit a flaw in the Prisma Access Agent network driver to bypass its security inspection mechanisms. Once bypassed, the attacker can inject, modify, or intercept network traffic that the agent should be protecting, potentially exfiltrating data or launching attacks on internal networks.
Prerequisites
  • Local administrator access on Windows machine
  • Prisma Access Agent version below 26.3 installed on Windows
local access requiredrequires administrator privilegeslow CVSS score (6.1)
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (6)
1 with fix5 pending
ProductAffected VersionsFix Status
Prisma Access AgentBelow 26.3 on Windows26.3 on Windows (ETA: 08/20)+
Prisma Access AgentNone on LinuxNo fix yet
Prisma Access AgentNone on macOSNo fix yet
Prisma Access AgentNone on iOSNo fix yet
Prisma Access AgentNone on AndroidNo fix yet
Prisma Access AgentNone on Chrome OSNo fix yet
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Prisma Access Agent
HOTFIXUpdate Prisma Access Agent to version 26.3 or later on all Windows endpoints
Long-term hardening
0/2
HARDENINGRestrict local administrator privileges on Windows endpoints to only users who require them
HARDENINGMonitor and audit local administrator account activity on Windows endpoints for suspicious network traffic manipulation
API: /api/v1/advisories/2cafd9c2-c687-434e-9d14-baebfe3f8557

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.