Prisma Access Agent: Local Privilege Escalation

Plan PatchCVSS 8.5CVE-2026-0294Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A privilege escalation vulnerability in the Palo Alto Networks Prisma Access Agent on Windows and macOS allows a local user to execute code with elevated system privileges. Linux, iOS, Android, and Chrome OS versions are not affected. The vulnerability enables an attacker with local user access to bypass security controls and gain full control of the endpoint.

What this means
What could happen
A local user on a Windows or macOS endpoint running the Prisma Access Agent could escalate their privileges and run arbitrary code with admin rights, potentially compromising the entire endpoint and gaining access to network resources your VPN protects.
Who's at risk
Any organization using Palo Alto Prisma Access Agent on Windows or macOS endpoints for remote VPN access. This includes staff working from home, branch offices, or on mobile devices connecting to your network. Linux, iOS, Android, and Chrome OS users are not affected.
How it could be exploited
An attacker with local user access to a Windows or macOS machine would run a malicious command or script that exploits the privilege escalation flaw in the Prisma Access Agent to gain system/administrator privileges, then execute arbitrary code to install malware, steal data, or pivot to your network.
Prerequisites
  • Local user account on Windows or macOS endpoint
  • Prisma Access Agent installed and running on the endpoint
  • Ability to execute commands on the local machine
Requires local user accessLow complexity attackAffects remote access securityNo fix available for Linux/iOS/Android/Chrome OS
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (6)
2 with fix4 pending
ProductAffected VersionsFix Status
Prisma Access AgentBelow 26.3 on Windows26.3 on Windows (ETA: 08/20)+
Prisma Access AgentBelow 26.3 on macOS26.3 on macOS (ETA: 08/20)+
Prisma Access AgentNone on LinuxNo fix yet
Prisma Access AgentNone on iOSNo fix yet
Prisma Access AgentNone on AndroidNo fix yet
Prisma Access AgentNone on Chrome OSNo fix yet
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Prisma Access Agent
HOTFIXUpdate Prisma Access Agent to version 26.3 or later on all Windows endpoints
HOTFIXUpdate Prisma Access Agent to version 26.3 or later on all macOS endpoints
Long-term hardening
0/2
Prisma Access Agent
HARDENINGReview and disable unnecessary local user accounts on endpoints running Prisma Access Agent
All products
HARDENINGRestrict local admin privileges on Windows and macOS endpoints to only necessary users; enforce least-privilege user accounts
API: /api/v1/advisories/47578557-9765-4427-ad66-97ef52afa602

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Prisma Access Agent: Local Privilege Escalation | CVSS 8.5 - OTPulse