CVE-2026-0306: Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows (Severity: MEDIUM)
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data.
This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2 - Upgrade
Upgrade
Prisma Access Agent (Windows)to a version that resolves this vulnerability.Fixed in 26.2
Event History
Frequently Asked Questions
Which systems are affected by this issue?
The issue affects Prisma Access Agent on Windows. Prisma Access Agent on macOS, Linux, iOS, Android, and Chrome OS is not affected.
What level of access does an attacker need?
An attacker needs local user access to the affected Windows system. No user interaction is required for exploitation.
What is the practical impact of successful exploitation?
A local user can bypass configured EndPoint DLP policy enforcement controls and exfiltrate sensitive data.