CVE-2026-0245: Prisma Access Agent: Information Disclosure Vulnerabilities (Severity: MEDIUM)
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials.
The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.1 - Upgrade
Upgrade
Prisma Access Agent on Windowsto a version that resolves this vulnerability.Fixed in 26.2.1 - Upgrade
Upgrade
Prisma Access Agent on macOSto a version that resolves this vulnerability.Fixed in 26.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0245?
CVE-2026-0245 has a medium severity rating.
What types of devices are affected by CVE-2026-0245?
CVE-2026-0245 affects the Prisma Access Agent on Linux, ChromeOS, Android, and iOS devices.
How do I fix CVE-2026-0245?
To fix CVE-2026-0245, upgrade the Prisma Access Agent to version 26.2.1 or later.
What kind of vulnerabilities are included in CVE-2026-0245?
CVE-2026-0245 includes multiple information disclosure vulnerabilities.
Can a local user exploit CVE-2026-0245?
Yes, a local user can exploit CVE-2026-0245 to access sensitive configuration data and credentials.