---
id: CVE-2026-0292
title: >-
  An authentication bypass vulnerability in the network driver of Palo Alto
  Networks Prisma® Access Agent on Windows enables a local administrator to
  bypass security inspection, subsequently allowing them to  inject and
  intercept arbitrary…
summary: >-
  An authentication bypass vulnerability in the network driver of Palo Alto
  Networks Prisma® Access Agent on Windows enables a local administrator to
  bypass security inspection, subsequently allowing them to  inject and
  intercept arbitrary…
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-290
vendor: paloaltonetworks
product: prisma_access_agent
affected:
  - prisma_access_agent < 26.3
patched:
  - prisma_access_agent 26.3
published: '2026-08-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:31:10.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0292'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0292'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
  - cve.org
  - score-dispute
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-13T13:24:21.943544Z'
scores:
  nvd: 6
  cna: 2.1
ingestedAt: '2026-09-13T03:20:02.783Z'
epss: 0.0013
epssPercentile: 0.02131
---

## Overview

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to  inject and intercept arbitrary network traffic.

The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

## Affected

- `prisma_access_agent < 26.3`

## Remediation

Upgrade past the affected range:

- `prisma_access_agent 26.3`
