Authentication Bypass by Spoofing in Prisma Access Agent on Windows - CVE-2026-0292

 

Authentication Bypass by Spoofing in Prisma Access Agent on Windows - CVE-2026-0292

Published: August 16, 2026


Vulnerability identifier: #VU143213
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0292
CWE-ID: CWE-290
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to bypass security inspection and inject and intercept arbitrary network traffic.

The vulnerability exists due to authentication bypass by spoofing in the network driver when handling network traffic for inspection. A local privileged user can spoof authentication in the driver to bypass security inspection and inject and intercept arbitrary network traffic.

No special configuration is required to be affected by this issue.


Affected software

Prisma Access Agent on Windows

How to mitigate CVE-2026-0292

Install security update from vendor's website.

Prisma Access Agent on Windows - update to 26.3

External References

Related Security Bulletins