Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
Plan PatchCVSS 8.3CVE-2026-0293Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
A vulnerability in Palo Alto Networks Prisma Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
What this means
What could happen
An attacker with administrator-level access to a Windows computer running Prisma Access Agent could bypass security protections and gain unauthorized access to the agent's processes and data, potentially compromising the security of the endpoint and any connected industrial networks.
Who's at risk
Organizations using Palo Alto Networks Prisma Access Agent on Windows endpoints are affected. This includes utilities and facilities management companies with remote workforce access, as well as any industrial environment where Windows computers connect to corporate networks protected by Prisma Access. Linux, macOS, iOS, Android, and Chrome OS deployments are not vulnerable.
How it could be exploited
An attacker who already has local administrator access to a Windows system runs commands or uses tools to exploit the anti-tamper bypass vulnerability, allowing them to modify or disable the Prisma Access Agent's security features and access its protected processes and files.
Prerequisites
- Local administrator privileges on the Windows system running Prisma Access Agent
- Physical or remote access to the Windows endpoint with ability to execute commands with administrative rights
requires local administrator privilegesaffects endpoint security agent
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (6)
1 with fix5 pending
ProductAffected VersionsFix Status
Prisma Access AgentBelow 26.3 on Windows26.3 on Windows (ETA: 08/20)+
Prisma Access AgentNone on LinuxNo fix yet
Prisma Access AgentNone on macOSNo fix yet
Prisma Access AgentNone on iOSNo fix yet
Prisma Access AgentNone on AndroidNo fix yet
Prisma Access AgentNone on Chrome OSNo fix yet
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Prisma Access Agent
HOTFIXUpdate Prisma Access Agent to version 26.3 or later on all Windows endpoints
Long-term hardening
0/2Prisma Access Agent
HARDENINGRestrict local administrator account creation and access on endpoints running Prisma Access Agent using domain group policies
HARDENINGImplement endpoint detection and response (EDR) to monitor for unauthorized modifications to Prisma Access Agent processes and files
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/171f4ce1-7520-4bb9-8035-419709eab5a8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.