CVE-2026-0268

EUVD-2026-36144
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.



This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
paloaltonetworksprisma_access_agent
25.7 ≤
𝑥
< 26.2.1
𝑥
= Vulnerable software versions