Local User Bypass of DLP Enforcement in Palo Alto Prisma Access Agent
CVE-2026-0306 Published on September 10, 2026
Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data.
This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Vulnerability Analysis
CVE-2026-0306 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Timeline
Initial Publication
Weakness Type
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.
Products Associated with CVE-2026-0306
Want to know whenever a new CVE is published for Palo Alto Networks Prisma Access Agent? stack.watch will email you.
Affected Versions
Palo Alto Networks Prisma Access Agent:- Before 26.2 is affected.
- Version All and below 6.3.3-h15 is unaffected.