Palo Alto Networks Prisma Access Agent Endpoint DLP Authorization Bypass Vulnerabilities

Vulnerability

Multiple authorization bypass vulnerabilities have been identified in the Endpoint DLP component of Prisma Access Agent, affecting versions 25.0.0 prior to 26.2.1 on both macOS and Windows. These vulnerabilities allow local attackers to bypass authentication controls and execute privileged operations. The issue arises when Endpoint DLP is enabled, creating an opportunity for privilege abuse by exploiting missing authentication for critical functions.

Impact

Exploitation of these vulnerabilities could lead to unauthorized access to privileged operations, allowing local attackers to manipulate or control aspects of the application or system that are normally restricted.

Remediation

Users can upgrade to version 26.2.1 or later to address these vulnerabilities. Instructions for downloading the latest version can be found on the Palo Alto Networks support site.

Added: May 13, 2026, 7:41 PM
Updated: May 13, 2026, 7:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
8.2
threat
0.0
urgency
5.7
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.