Local User Bypass of DLP Enforcement in Palo Alto Prisma Access Agent
CVE-2026-0306 Published on September 10, 2026

Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-0306 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Timeline

Initial Publication

Weakness Type

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.


Products Associated with CVE-2026-0306

Want to know whenever a new CVE is published for Palo Alto Networks Prisma Access Agent? stack.watch will email you.

 

Affected Versions

Palo Alto Networks Prisma Access Agent: Palo Alto Networks Prisma Access Agent: