CVE-2026-0268: Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux (Severity: MEDIUM)
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.
This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.1 - Upgrade
Upgrade
Prisma Access Agent for Linuxto a version that resolves this vulnerability.Fixed in 26.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0268?
CVE-2026-0268 has a severity rating of medium with a CVSS score of 6.9.
How does CVE-2026-0268 affect Linux users?
CVE-2026-0268 allows local attackers on Linux to route network traffic outside the VPN tunnel, posing a security risk.
How do I fix CVE-2026-0268?
To remediate CVE-2026-0268, upgrade the Prisma Access Agent on Linux to version 26.2.1 or later.
Are there any workarounds for CVE-2026-0268?
There are no known workarounds for CVE-2026-0268.
Does CVE-2026-0268 impact other operating systems?
CVE-2026-0268 does not affect Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.