SB20260816157 - Multiple vulnerabilities in Prisma Access Agent on Windows



SB20260816157 - Multiple vulnerabilities in Prisma Access Agent on Windows

Published: August 16, 2026

Security Bulletin ID SB20260816157
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Protection mechanism failure (CVE-ID: CVE-2026-0293)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to bypass anti-tamper protection and gain unauthorized access to protected processes and files.

The vulnerability exists due to protection mechanism failure in anti-tamper protection in Prisma Access Agent on Windows when enforcing protection for processes and files. A local privileged user can bypass the anti-tamper protection to bypass anti-tamper protection and gain unauthorized access to protected processes and files.

No special configuration is required to be affected by this issue.


2) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-0292)

CWE-ID: CWE-290 - Authentication Bypass by Spoofing

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to bypass security inspection and inject and intercept arbitrary network traffic.

The vulnerability exists due to authentication bypass by spoofing in the network driver when handling network traffic for inspection. A local privileged user can spoof authentication in the driver to bypass security inspection and inject and intercept arbitrary network traffic.

No special configuration is required to be affected by this issue.


Remediation

Install update from vendor's website.