Improper Protection of Alternate Path in Prisma Access Agent for Linux - CVE-2026-0268

 

Improper Protection of Alternate Path in Prisma Access Agent for Linux - CVE-2026-0268

Published: June 16, 2026


Vulnerability identifier: #VU134589
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0268
CWE-ID: CWE-424
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to route network traffic outside the VPN tunnel.

The vulnerability exists due to improper protection of alternate path in Prisma Access Agent for Linux when enforcing VPN traffic routing. A local user can bypass VPN enforcement to route network traffic outside the VPN tunnel.

No special configuration is required.


Affected software

Prisma Access Agent for Linux

How to mitigate CVE-2026-0268

Install security update from vendor's website.

Prisma Access Agent for Linux - update to 26.2.1

External References

Related Security Bulletins