CVE-2026-0306 PUBLISHED

Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows

Assigner: palo_alto
Reserved: 03.11.2025 Published: 10.09.2026 Updated: 10.09.2026

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data.

This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 5.8

Product Status

Vendor Palo Alto Networks
Product Prisma Access Agent
Versions Default: unaffected
  • affected from 0 to 26.2 (excl.)
Vendor Palo Alto Networks
Product Prisma Access Agent
Versions Default: unaffected
  • unaffected from All to 6.3.3-h15 (excl.)

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • Vladislav Ovitchinikov and Daniel Cuthbert finder

References

Problem Types

  • CWE-693 Protection Mechanism Failure CWE

Impacts

  • CAPEC-212 Functionality Misuse