A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data.
This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0306 |
|
History
Thu, 10 Sep 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected. | |
| Title | Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows | |
| First Time appeared |
Palo Alto Networks
Palo Alto Networks prisma Access Agent |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:android:*:*:*:*:* cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:chromeos:*:*:*:*:* cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:ios:*:*:*:*:* cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:linux:*:*:*:*:* cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:macos:*:*:*:*:* cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Palo Alto Networks
Palo Alto Networks prisma Access Agent |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2026-09-10T05:55:23.322Z
Reserved: 2025-11-03T20:45:04.920Z
Link: CVE-2026-0306
No data.
Status : Received
Published: 2026-09-10T06:17:03.007
Modified: 2026-09-10T06:17:03.007
Link: CVE-2026-0306
No data.
OpenCVE Enrichment
Updated: 2026-09-10T07:30:07Z
Weaknesses