Insecure DLL loading in Prisma Access Agent on Windows and Prisma Access Agent on macOS - CVE-2026-0294

 

Insecure DLL loading in Prisma Access Agent on Windows and Prisma Access Agent on macOS - CVE-2026-0294

Published: August 16, 2026


Vulnerability identifier: #VU143211
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0294
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to uncontrolled search path element in Prisma Access Agent app when loading resources on the local system. A local userr can place a malicious file in a searched path to execute code with elevated privileges.

No special configuration is required to be affected by this issue.


Affected software

Prisma Access Agent on Windows
Prisma Access Agent on macOS

How to mitigate CVE-2026-0294

Install security update from vendor's website.

Prisma Access Agent on Windows - update to 26.3
Prisma Access Agent on macOS - update to 26.3

External References

Related Security Bulletins