Insecure DLL loading in Prisma Access Agent on Windows and Prisma Access Agent on macOS - CVE-2026-0294
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to uncontrolled search path element in Prisma Access Agent app when loading resources on the local system. A local userr can place a malicious file in a searched path to execute code with elevated privileges.
No special configuration is required to be affected by this issue.
Affected software
Prisma Access Agent on macOS
How to mitigate CVE-2026-0294
Prisma Access Agent on macOS - update to 26.3