Prisma Access Agent: Information Disclosure Vulnerability on Linux

MonitorCVSS 6.8CVE-2026-0305Sep 9, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A vulnerability in Palo Alto Networks Prisma Access Agent on Linux allows a local user to access sensitive configuration data and credentials stored by the agent. This occurs because the agent stores configuration information in files that are readable by any local user on the system. The vulnerability affects Prisma Access Agent versions below 26.3 on Linux. macOS, Windows, iOS, Android, and Chrome OS versions are not affected.

What this means
What could happen
A local user on a Linux machine running Prisma Access Agent could read sensitive configuration files and credentials stored by the agent, potentially gaining unauthorized access to protected networks or systems that the agent connects to.
Who's at risk
IT administrators managing remote workforce access through Palo Alto Prisma Access, particularly organizations that deploy the Linux-based Prisma Access Agent on employee laptops or jump servers. macOS, Windows, iOS, Android, and ChromeOS platforms are not affected by this vulnerability.
How it could be exploited
An attacker with local access to a Linux system running the Prisma Access Agent can read unprotected files in the agent's configuration directories to extract credentials and settings that allow connection to protected corporate networks. The agent stores this information in a way that any local user can access, bypassing the intended access controls.
Prerequisites
  • Local user account on the Linux system running Prisma Access Agent
  • Ability to read files in the agent's configuration directory
Requires local system accessAffects credential securityLinux-only vulnerability
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (6)
1 with fix5 pending
ProductAffected VersionsFix Status
Prisma Access AgentBelow 26.3 on Linux26.3 on Linux+
Prisma Access AgentNone on macOSNo fix yet
Prisma Access AgentNone on WindowsNo fix yet
Prisma Access AgentNone on iOSNo fix yet
Prisma Access AgentNone on AndroidNo fix yet
Prisma Access AgentNone on ChromeOSNo fix yet
Remediation & Mitigation
0/3
Do now
0/1
Prisma Access Agent
HARDENINGRestrict local file system access to Prisma Access Agent configuration directories through file permissions or AppArmor/SELinux profiles to prevent unauthorized local users from reading sensitive files
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Prisma Access Agent
HOTFIXUpdate Prisma Access Agent to version 26.3 or later on all Linux endpoints
All products
HARDENINGAudit Linux systems for unauthorized local user access and review credential usage logs for any suspicious remote access attempts
API: /api/v1/advisories/2f99838b-324a-4322-9965-b2eaacaec3bb

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.