{"id":"CVE-2026-0292","title":"An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to  inject and intercept arbitrary…","summary":"An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to  inject and intercept arbitrary…","severity":"medium","cvss":6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-290"],"vendor":"paloaltonetworks","product":"prisma_access_agent","affected":["prisma_access_agent < 26.3"],"patched":["prisma_access_agent 26.3"],"published":"2026-08-13","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:31:10.667","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0292","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0292","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org","score-dispute"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-13T13:24:21.943544Z"},"scores":{"nvd":6,"cna":2.1},"ingestedAt":"2026-09-13T03:20:02.783Z","epss":0.0013,"epssPercentile":0.02985,"slug":"CVE-2026-0292","body":"## Overview\n\nAn authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to  inject and intercept arbitrary network traffic.\n\nThe Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.\n\n## Affected\n\n- `prisma_access_agent < 26.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `prisma_access_agent 26.3`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}