{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-0278","assignerOrgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","state":"PUBLISHED","assignerShortName":"palo_alto","dateReserved":"2025-11-03T20:44:37.292Z","datePublished":"2026-07-09T19:12:11.045Z","dateUpdated":"2026-07-11T03:55:14.977Z"},"containers":{"cna":{"providerMetadata":{"orgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","shortName":"palo_alto","dateUpdated":"2026-07-09T19:12:11.045Z"},"title":"Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows","datePublic":"2026-07-08T16:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-693","description":"CWE-693 Protection Mechanism Failure","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-212","descriptions":[{"lang":"en","value":"CAPEC-212 Functionality Misuse"}]}],"affected":[{"vendor":"Palo Alto Networks","product":"Prisma Access Agent","versions":[{"status":"affected","version":"24.0","lessThan":"26.2.1","changes":[{"at":"26.2.1","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected","platforms":["Windows"]},{"vendor":"Palo Alto Networks","product":"Prisma Access Agent","versions":[{"status":"unaffected","version":"All","versionType":"custom"}],"defaultStatus":"unaffected","platforms":["macOS"]}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:windows:*:*:*:*:*","versionStartIncluding":"24.0","versionEndExcluding":"26.2.1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:palo_alto_networks:prisma_access_agent:all:*:macos:*:*:*:*:*"}]}]}],"descriptions":[{"lang":"en","value":"Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.\n\n\n\nThe Prisma Access Agent on macOS is not affected.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p><span>Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.</span></p><p><span>The Prisma Access Agent on macOS is not affected.</span></p>"}]}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0278","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"AUTOMATIC","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"HIGH","providerUrgency":"AMBER","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.8,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:C/RE:H/U:Amber"}}],"configurations":[{"lang":"eng","value":"No special configuration is required to be affected by this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"No special configuration is required to be affected by this issue."}]}],"workarounds":[{"lang":"en","value":"No known workarounds exist for this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"No known workarounds exist for this issue."}]}],"solutions":[{"lang":"eng","value":"Version\nMinor Version\nSuggested Solution\n\n                                    Prisma Access Agent   on Windows\n\n                                    24.0 through 26.2\n                                    Upgrade to 26.2.1 or later.\n                                Prisma Access Agent on macOS\nNo action needed.","supportingMedia":[{"type":"text/html","base64":false,"value":"<table><thead><tr><th>Version<br></th><th>Minor Version<br></th><th>Suggested Solution<br></th></tr></thead><tbody><tr>\n                                    <td>Prisma Access Agent   on Windows<br></td>\n                                    <td>24.0 through 26.2</td>\n                                    <td>Upgrade to 26.2.1 or later.</td>\n                                </tr><tr><td>Prisma Access Agent on macOS<br></td><td></td><td>No action needed.</td></tr></tbody></table>"}]}],"exploits":[{"lang":"en","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}]}],"timeline":[{"time":"2026-07-08T16:00:00.000Z","lang":"en","value":"Initial Publication"}],"credits":[{"lang":"en","value":"Daniel Cuthbert and Vladislav Ovitchinikov from Banco Santander","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-08T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-0278"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-11T03:55:14.977Z"}}]}}