Link following in Prisma Access Agent on Linux - CVE-2026-0291
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to delete system files in a limited scope and disable Prisma Access Agent.
The vulnerability exists due to improper link resolution before file access in Prisma Access Agent on Linux when handling file access operations. A local user can leverage a symlink attack to delete system files in a limited scope and disable Prisma Access Agent.
No special configuration is required to be affected by this issue.