Palo Alto Networks Prisma® Access Agent 的端点数据防泄漏(DLP)执行机制中存在一个漏洞,允许本地用户绕过已配置的 DLP 策略控制,从而泄露敏感数据。 在 macOS、Linux、iOS、Android 和 Chrome OS 上的 Prisma Access Agent 不受此漏洞影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Prisma Access Agent | 0 ~ 26.2 | - |
|
| Palo Alto Networks | Prisma Access Agent | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0307 | 5.9 MEDIUM | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-0310 | 5.2 MEDIUM | PAN-OS: Buffer Overflow Vulnerability via XML Processing |
| CVE-2026-0304 | 4.8 MEDIUM | Cortex XDR Broker VM: Privilege Escalation Vulnerability |
| CVE-2026-0305 | 4.3 MEDIUM | Prisma Access Agent: Information Disclosure Vulnerability on Linux |
| CVE-2026-0309 | 4.0 MEDIUM | PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration |
| CVE-2026-0303 | 2.4 LOW | Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File |
| CVE-2026-0302 | 1.1 LOW | Checkov by Prisma Cloud: OS Command Injection Vulnerability |
| CVE-2026-0308 | 0.4 LOW | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface |
No comments yet