CVE-2026-0235: Prisma Browser: Access and Data Rule Bypass
Published May 13, 2026
·Updated
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.
Affected Software
2 affected components
Palo Alto Networks Prisma Browser
Palo Alto Networks Prisma Browser <146.10.7.154
Event History
May 13, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0235?
CVE-2026-0235 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to data.
2
How do I fix CVE-2026-0235?
To fix CVE-2026-0235, you should apply the latest security patches provided by Palo Alto Networks for Prisma Browser.
3
Who is affected by CVE-2026-0235?
CVE-2026-0235 affects locally authenticated non-admin users of the Palo Alto Networks Prisma Browser.
4
What types of policies can be bypassed due to CVE-2026-0235?
CVE-2026-0235 allows the bypassing of certain access and data control policies within the Prisma Browser.
5
When was CVE-2026-0235 published?
CVE-2026-0235 was published as part of Palo Alto Networks' ongoing security updates and advisories.