CVE-2026-0246: Prisma Access Agent: Local Privilege Escalation Vulnerability (Severity: MEDIUM)
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.
The Prisma Access Agent on iOS, Android and Chrome OS are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.1 - Upgrade
Upgrade
Palo Alto Networks Prisma Access Agent (Linux)to a version that resolves this vulnerability.Fixed in 26.2.1 - Upgrade
Upgrade
Palo Alto Networks Prisma Access Agent (Windows)to a version that resolves this vulnerability.Fixed in 26.2.1 - Upgrade
Upgrade
Palo Alto Networks Prisma Access Agent (macOS)to a version that resolves this vulnerability.Fixed in 26.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0246?
The severity of CVE-2026-0246 is classified as MEDIUM.
What is CVE-2026-0246?
CVE-2026-0246 is a local privilege escalation vulnerability in the Palo Alto Networks Prisma Access Agent that allows non-administrative users to escalate privileges to root on macOS and Linux.
How do I fix CVE-2026-0246?
To fix CVE-2026-0246, upgrade to version 26.2.1 or later of the Prisma Access Agent.
Who is affected by CVE-2026-0246?
CVE-2026-0246 affects users of the Palo Alto Networks Prisma Access Agent on macOS, Linux, and Windows.
Can CVE-2026-0246 be exploited remotely?
CVE-2026-0246 requires local authentication to be exploited, meaning it cannot be exploited remotely.