Description
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 26.2.1
All (custom)
Timeline
| 2026-05-13: | Initial publication. |
Credits
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
References
security.paloaltonetworks.com/CVE-2026-0245