CVE-2026-0291

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:paloaltonetworks:prisma_access_agent:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 03:16

Updated : 2026-09-09 16:33


NVD link : CVE-2026-0291

Mitre link : CVE-2026-0291

CVE.ORG link : CVE-2026-0291


JSON object : View

Products Affected

linux

  • linux_kernel

paloaltonetworks

  • prisma_access_agent
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')