It's like discovering a secret door in a vault that only opens if you already have the master key
CVE-2026-0292 is an authentication bypass (CWE-290) in the network driver of Palo Alto Networks Prisma Access Agent on Windows. Versions 24.0 through 26.2.2 are affected. A local administrator can exploit this flaw to bypass the agent's security inspection engine, allowing them to inject and intercept arbitrary network traffic that would otherwise be inspected and enforced by the SASE tunnel. The fix is version 26.3, with an ETA of August 20, 2026. Only Windows is affected — Linux, macOS, iOS, Android, and ChromeOS are not vulnerable.
Palo Alto's own CVSS 4.0 Base score is 6.1, but after applying their Threat adjustment (no known exploitation, automatic remediation available, confirmed fix) they land on a CVSS-BT of 2.1 / LOW with *moderate* urgency. That LOW rating is defensible: the attack requires local administrator privileges, which means the attacker has already deeply compromised the endpoint. The incremental value of this CVE over what a local admin can already do (disable services, modify drivers, kill agent processes) is narrow. However, this *is* a security inspection bypass in a network-level agent, meaning a sophisticated post-compromise actor could use it to evade DLP and threat inspection silently — without triggering the tamper-protection alerts that cruder methods would fire. That nuance bumps it above LOW into MEDIUM territory in our assessment.
3 steps from start to impact.
Obtain local administrator on Windows endpoint
- Local administrator access on a Windows endpoint running Prisma Access Agent 24.0–26.2.2
- Requires prior compromise — this is a post-exploitation technique, not initial access
- Enterprise environments with PAM/LAPS reduce the availability of standing local admin credentials
Interact with Prisma Access Agent network driver
- Prisma Access Agent service is running and the network driver is loaded
- Knowledge of the driver interface (requires reverse engineering or leaked advisory details)
- No public PoC or exploit code exists as of disclosure date
- The driver interface details are not publicly documented, raising the bar for exploitation
- Prisma Access Agent tamper protection may log or alert on unusual driver interactions
Bypass security inspection and inject/intercept traffic
- Successful exploitation of CVE-2026-0292
- Network-level controls (firewall, proxy, NAC) independent of the agent still apply
- If the enterprise uses split-tunnel with allow-list, only approved destinations are reachable even without inspection
- EDR on the same host still monitors process and file activity independently
The supporting signals.
| In-the-Wild Exploitation | None reported. Palo Alto confirms no known malicious exploitation. Not listed on CISA KEV. |
|---|---|
| Proof-of-Concept | No public PoC as of 2026-08-13. The network driver interface is undocumented, raising the reverse-engineering bar. |
| EPSS Score | Not yet scored — CVE disclosed today (2026-08-13). Expect a low EPSS given local/admin prerequisites. |
| KEV Status | Not listed. No CISA KEV entry. |
| CVSS Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:L — Base 6.1, Threat-adjusted (BT) 2.1. Local access, high privileges, no user interaction. Subsequent system impact is high for integrity and confidentiality. |
| Affected Versions | Prisma Access Agent for Windows versions 24.0 through 26.2.2 |
| Fixed Version | 26.3 (ETA: August 20, 2026). No backports announced. No workarounds available. |
| Exposure Data | Prisma Access Agent is an endpoint agent, not internet-facing. No Shodan/Censys/GreyNoise exposure relevant. Palo Alto claims tens of thousands of enterprise deployments of Prisma Access. |
| Disclosure Date | 2026-08-13 (today). Coordinated disclosure by Palo Alto Networks. |
| Reporter | Not publicly attributed in the advisory. |
noisgate verdict.
The single most decisive factor is the local administrator prerequisite: an attacker who already holds local admin on a Windows endpoint has extensive existing capabilities to disable or circumvent security tooling, making the incremental risk of this specific inspection bypass narrow. The security-agent-bypass nature of the flaw prevents a LOW rating, but the lack of any remote attack surface or privilege escalation keeps it firmly in MEDIUM.
Why this verdict
- Local admin prerequisite (AV:L/PR:H): The attacker must already have the highest local privilege level on the endpoint. This is not initial access — it is deep post-compromise. Every enterprise EDR should detect the chain that grants admin before this CVE is even reachable.
- No remote attack surface: This cannot be triggered over the network. There is zero exposure to internet-facing scanners or drive-by exploitation. The reachable attacker population is limited to those who have already compromised the specific endpoint.
- Security agent bypass — floor anchor: Prisma Access Agent is a security inspection component. Bypassing it silently (without triggering tamper alerts) has post-compromise evasion value for APT-grade actors. This prevents dropping to LOW despite the heavy friction.
- Role multiplier: Prisma Access Agent runs on endpoints (laptops, workstations, occasionally VDI). It is not a domain controller, hypervisor, or identity provider. The blast radius of bypassing inspection on one endpoint is host-scoped — the attacker evades DLP/threat-inspection on that single host's traffic. There is no lateral or fleet-scale amplification from this CVE alone. The high-value role floor (CRITICAL/HIGH) does not apply because the component is an endpoint agent, not a control-plane or identity-tier asset.
- No exploitation, no PoC, no KEV: Zero evidence of weaponization. The driver interface is undocumented. Exploitation requires reverse engineering effort with no public guidance.
Why not higher?
This is not HIGH because the vulnerability requires local administrator access — a position that already grants the attacker extensive control over the endpoint, including the ability to disable services, unload drivers, or kill agent processes through other means. The blast radius is limited to a single endpoint's traffic inspection, with no privilege escalation, no lateral movement enablement, and no remote trigger. No exploitation exists in the wild.
Why not lower?
This is not LOW because the flaw resides in a security inspection component's network driver. A clean, silent bypass of traffic inspection — one that doesn't trigger tamper-protection alerts the way killing the service would — has genuine operational value for sophisticated post-compromise actors conducting data exfiltration or C2 communication. The affected version range spans over two years of releases (24.0–26.2.2), meaning a large installed base is vulnerable. The vendor's own CVSS Base of 6.1 (before threat adjustment) acknowledges the subsequent-system impact is high.
What to do — in priority order.
- Monitor Prisma Access Agent health telemetry for inspection-volume anomalies — Configure your Prisma Access management console to alert when an endpoint's inspected traffic volume drops to zero or significantly below baseline. This detects the bypass in action. No mitigation SLA applies for MEDIUM — go straight to remediation within 365 days.
- Enforce least-privilege and remove standing local admin — Deploy LAPS or a PAM solution (CyberArk, BeyondTrust) to eliminate standing local administrator credentials. This cuts off the prerequisite for the attack. This is a strategic control, not a CVE-specific workaround.
- Layer network-level inspection independent of the endpoint agent — Ensure a cloud proxy, NGFW, or CASB inspects traffic at the network perimeter independently of the endpoint agent. If the agent is bypassed, the network-tier inspection still catches malicious traffic.
- Upgrade to Prisma Access Agent 26.3 when available (ETA 2026-08-20) — Palo Alto confirms no workaround exists. The only remediation is upgrading to 26.3. Plan deployment within the 365-day noisgate remediation SLA for MEDIUM, though upgrading promptly when the patch drops on Aug 20 is prudent.
- Restarting the Prisma Access Agent service — the vulnerability is in the network driver, not the service process. Restarting the service does not re-authenticate the driver control path.
- Application whitelisting / AppLocker — the attacker is already a local administrator and can modify AppLocker policies or use trusted binaries to interact with the driver.
- Network segmentation alone — while helpful for limiting lateral movement, it does not restore the bypassed inspection on the compromised endpoint's own traffic.
Crowdsourced verification payload.
Run this on each Windows endpoint where Prisma Access Agent is installed. Requires standard user privileges (reads registry/file version only). Example: powershell -ExecutionPolicy Bypass -File .\Check-CVE-2026-0292.ps1
#Requires -Version 5.1
# Check-CVE-2026-0292.ps1
# Checks if Prisma Access Agent on Windows is vulnerable to CVE-2026-0292
# Output: VULNERABLE / PATCHED / UNKNOWN
# Exit codes: 1 = VULNERABLE, 0 = PATCHED, 2 = UNKNOWN
$ErrorActionPreference = 'Stop'
try {
# Common install paths for Prisma Access Agent
$paths = @(
"$env:ProgramFiles\Palo Alto Networks\Prisma Access Agent",
"${env:ProgramFiles(x86)}\Palo Alto Networks\Prisma Access Agent"
)
$agentExe = $null
foreach ($p in $paths) {
$candidate = Join-Path $p 'PrismaAccessAgent.exe'
if (Test-Path $candidate) {
$agentExe = $candidate
break
}
}
if (-not $agentExe) {
# Try registry
$regPaths = @(
'HKLM:\SOFTWARE\Palo Alto Networks\Prisma Access Agent',
'HKLM:\SOFTWARE\WOW6432Node\Palo Alto Networks\Prisma Access Agent'
)
foreach ($rp in $regPaths) {
if (Test-Path $rp) {
$installDir = (Get-ItemProperty -Path $rp -ErrorAction SilentlyContinue).InstallDir
if ($installDir -and (Test-Path (Join-Path $installDir 'PrismaAccessAgent.exe'))) {
$agentExe = Join-Path $installDir 'PrismaAccessAgent.exe'
break
}
}
}
}
if (-not $agentExe) {
Write-Host 'UNKNOWN - Prisma Access Agent not found on this host'
exit 2
}
$ver = (Get-Item $agentExe).VersionInfo.ProductVersion
if (-not $ver) {
$ver = (Get-Item $agentExe).VersionInfo.FileVersion
}
if (-not $ver) {
Write-Host "UNKNOWN - Could not determine Prisma Access Agent version from $agentExe"
exit 2
}
Write-Host "Detected Prisma Access Agent version: $ver"
try {
$parsed = [System.Version]($ver -replace '[^0-9.]', '')
} catch {
Write-Host "UNKNOWN - Could not parse version string: $ver"
exit 2
}
# Affected: 24.0 through 26.2.2
# Fixed: 26.3+
$minAffected = [System.Version]'24.0'
$fixedVersion = [System.Version]'26.3'
if ($parsed -ge $fixedVersion) {
Write-Host "PATCHED - Version $ver is >= 26.3 (fixed)"
exit 0
} elseif ($parsed -ge $minAffected) {
Write-Host "VULNERABLE - Version $ver is in affected range 24.0 - 26.2.2 (CVE-2026-0292)"
exit 1
} else {
Write-Host "UNKNOWN - Version $ver is below 24.0; not in documented affected range"
exit 2
}
} catch {
Write-Host "UNKNOWN - Error during check: $_"
exit 2
}If you remember one thing.
Sources
What defenders are saying.
Crowdsourced verification outputs.
Results submitted by users who ran the verification payload against their environment.