Protection mechanism failure in Prisma Access Agent on Windows - CVE-2026-0306
Published: September 14, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the EndPoint Data Loss Prevention (DLP) enforcement. A local user can bypass configured DLP policy enforcement controls and exfiltrate sensitive data.