CVE-2026-0291: Prisma Access Agent: Authenticated Limited File Deletion on Linux (Severity: LOW)
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.
The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.2 - Upgrade
Upgrade
Palo Alto Networks Prisma Access Agent (Linux)to a version that resolves this vulnerability.Fixed in 26.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0291?
CVE-2026-0291 has a severity rating of medium with a score of 4.8.
What type of vulnerability is CVE-2026-0291?
CVE-2026-0291 is an improper link resolution before file access vulnerability.
How can CVE-2026-0291 be exploited?
CVE-2026-0291 can be exploited by a local low privileged user to delete system files in a limited scope.
Which software is affected by CVE-2026-0291?
CVE-2026-0291 affects the Palo Alto Networks Prisma Access Agent on Linux platforms.
How can I mitigate the risks associated with CVE-2026-0291?
To mitigate the risks of CVE-2026-0291, ensure that only trusted users have access to the affected systems and apply any available security patches from Palo Alto Networks.