Local DLP Enforcement Bypass in Palo Alto Networks Prisma Access Agent on Windows

What is CVE-2026-0306?

CVE-2026-0306 is a vulnerability classified as Protection Mechanism Failure, affecting Prisma Access Agent. This vulnerability is rated Medium, with a CVSS score of 5.8. There is not enough data to determine whether this vulnerability has been exploited.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.

Affected products and scope

  • Prisma Access Agent on Windows: versions before 26.2 are affected; 26.2 and versions listed by the vendor from that boundary onward are unaffected.
  • Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS: the vendor lists all versions as unaffected.
  • No special configuration is required for a deployment to be exposed.

Technical details

The affected component is EndPoint Data Loss Prevention (DLP) enforcement in Palo Alto Networks Prisma Access Agent on Windows. A local user with low privileges can bypass configured DLP policy enforcement controls and may exfiltrate sensitive data. The available evidence describes local reachability, low attack complexity, no user interaction, and no special configuration requirement for exposure. The weakness is classified as CWE-693, Protection Mechanism Failure. The available sources do not identify the attacker-controlled input, specific endpoint, code path, or implementation detail that enables the bypass. Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is identified as unaffected.

Exploitability

The issue is locally reachable rather than remotely reachable over the network. Exploitation requires a local user or process with low privileges, does not require user interaction, and has no stated special attack requirements. The vendor states that it is not aware of malicious exploitation of this issue and characterizes the issue as not automatable. The supplied record does not establish a public exploit, campaign, victim, or specific breach, so those statuses remain unknown.

Technical impact

The flaw weakens the product's DLP protection mechanism, so a local user with access to an affected endpoint may defeat policies intended to prevent sensitive data from leaving the endpoint. The structured impact assessment indicates high confidentiality and integrity impact within the product, with no availability impact. Because access is local and the required privilege level is low, the issue primarily concerns users or processes that already have access to the endpoint. The available evidence does not confirm broader system compromise, privilege escalation, or impact to platforms other than Windows. Possible organisational consequences include unauthorised disclosure, compliance failures, and investigation costs if protected data has left an endpoint.

Business impact

The primary business risk is failure of a preventive data-loss control on affected Windows endpoints. A local user may bypass DLP policy enforcement and move sensitive data outside approved controls, creating possible unauthorized disclosure, data-protection compliance exposure, and investigation or notification obligations. The issue does not by itself establish remote compromise, privilege escalation, or a confirmed breach. Linux, macOS, iOS, Android, and Chrome OS deployments are identified as unaffected.

Remediation

  1. Upgrade Prisma Access Agent on Windows to 26.2 or a version the vendor confirms from that boundary onward.
  2. Reconcile inventory for Linux, macOS, iOS, Android, and Chrome OS deployments; the vendor states that no action is needed for those platforms for this issue.
  3. If an immediate upgrade is not possible, note that the vendor lists no known workaround. Do not treat unvalidated DLP configuration changes as a substitute for the upgrade.

Detection

  1. Inventory Windows systems running Prisma Access Agent and compare their installed releases with the vendor's affected and fixed boundaries.
  2. Identify Windows endpoints enforcing DLP policies, then verify that observed enforcement behavior matches the configured policies.
  3. Review endpoint DLP and data-transfer telemetry for cases where sensitive data appears to leave the endpoint despite a policy that should block the action. This is precautionary monitoring, not a vendor-confirmed indicator of compromise.
  4. Do not treat the absence of unusual logs or events as proof of safety. The advisory does not provide a specific log signature, IOC, or event that confirms or rules out exploitation.
Sources (5)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard