Palo Alto Networks Prisma Access Agent是美国Palo Alto Networks公司的一款代理接入安全客户端。 Palo Alto Networks Prisma Access Agent 26.3之前版本存在权限许可和访问控制问题漏洞,该漏洞源于权限提升问题,在Windows和macOS设备上,可能允许本地用户以提升的权限执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Palo Alto Networks | Prisma Access Agent | < 26.3 |
affected |
All |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Prisma Access Agent | 0 ~ 26.3 | - |
|
| Palo Alto Networks | Prisma Access Agent | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0299 | 5.9 MEDIUM | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-0293 | 5.6 MEDIUM | Prisma Access Agent: Anti-Tamper Protection Bypass on Windows |
| CVE-2026-0298 | 5.2 MEDIUM | GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP |
| CVE-2026-0297 | 5.2 MEDIUM | GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake |
| CVE-2026-0296 | 4.5 MEDIUM | GlobalProtect App: Improper Certificate Validation Bypass Vulnerability |
| CVE-2026-0295 | 4.1 MEDIUM | GlobalProtect App: Local Privilege Escalation via Race Condition on macOS |
| CVE-2026-0292 | 2.1 LOW | Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows |
| CVE-2026-0291 | 1.1 LOW | Prisma Access Agent: Authenticated Limited File Deletion on Linux |
| CVE-2026-0289 | 0.5 LOW | Prisma Browser: Inappropriate Implementation in Account Protection |
| CVE-2026-0301 | 0.5 LOW | PAN-OS: Information Disclosure Vulnerability in URL Filtering |
| CVE-2026-0290 | 0.5 LOW | Prisma Browser: Sensitive Information Disclosure Vulnerability |
No comments yet