← Back

Prisma Access Agent

prisma_access_agent

Vendor: Paloaltonetworks • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Prisma Access Agent
Jul 16, 2026
Jul 9, 2026
5.8 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not...Show more
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 16, 2026
Jul 9, 2026
5.7 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS,...Show more
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 10, 2026
Jun 10, 2026
5.9 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on W...Show more
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 13, 2026
Jun 10, 2026
4.4 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Androi...Show more
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 14, 2026
May 13, 2026
6.2 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificat...Show more
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 14, 2026
May 13, 2026
5.9 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.
1Paloaltonetworks
1Prisma Access Agent
Jul 14, 2026
May 13, 2026
5.9 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT A...Show more
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts. The Prisma Access Agent on iOS, Android and Chrome OS are not affected.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 14, 2026
May 13, 2026
4.3 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not a...Show more
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.Show less