CVE-2026-0305: Prisma Access Agent: Information Disclosure Vulnerability on Linux (Severity: MEDIUM)
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials.
The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.3 - Upgrade
Upgrade
Palo Alto Networks Prisma Access Agent (Linux)to a version that resolves this vulnerability.Fixed in 26.3
Event History
Frequently Asked Questions
Which systems are affected by this issue?
The issue affects the Palo Alto Networks Prisma Access Agent on Linux. The agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
What access does an attacker need to exploit this vulnerability?
An attacker needs local access as a user on an affected Linux system. The vulnerability allows that local user to access sensitive configuration data and credentials.