PT-2026-40770 · Palo Alto Networks · Prisma Access Agent

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-0246

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITYSYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.
The Prisma Access Agent on iOS, Android and Chrome OS are not affected.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-0246

Affected Products

Prisma Access Agent