{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-0293","assignerOrgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","state":"PUBLISHED","assignerShortName":"palo_alto","dateReserved":"2025-11-03T20:44:51.366Z","datePublished":"2026-08-13T01:51:07.249Z","dateUpdated":"2026-08-13T13:27:50.592Z"},"containers":{"cna":{"providerMetadata":{"orgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","shortName":"palo_alto","dateUpdated":"2026-08-13T01:51:07.249Z"},"title":"Prisma Access Agent: Anti-Tamper Protection Bypass on Windows","datePublic":"2026-08-12T16:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-693","description":"CWE-693 Protection Mechanism Failure","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-159","descriptions":[{"lang":"en","value":"CAPEC-159 Redirect Access to Libraries"}]}],"affected":[{"vendor":"Palo Alto Networks","product":"Prisma Access Agent","platforms":["Windows"],"versions":[{"status":"affected","version":"0","lessThan":"26.3","changes":[{"at":"26.3","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"Palo Alto Networks","product":"Prisma Access Agent","platforms":["Linux","macOS","iOS","Android","Chrome OS"],"versions":[{"status":"unaffected","version":"All","versionType":"custom"}],"defaultStatus":"unaffected"}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:Windows:*:*","versionEndExcluding":"26.2.2","versionStartIncluding":"24.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"descriptions":[{"lang":"en","value":"A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files.\n\nThe Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.","supportingMedia":[{"type":"text/html","base64":false,"value":"<span>A vulnerability in Palo Alto Networks <span>Prisma® Access Agent</span> on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files.</span><b><span><br></span><span><br></span></b><span>The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.</span>"}]}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0293","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"NOT_DEFINED","valueDensity":"DIFFUSE","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.6,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/V:D/RE:M/U:Amber"}}],"configurations":[{"lang":"eng","value":"No special configuration is required to be affected by this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"No special configuration is required to be affected by this issue."}]}],"workarounds":[{"lang":"eng","value":"No known workarounds exist for this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"No known workarounds exist for this issue."}]}],"solutions":[{"lang":"eng","value":"VERSION                            MINOR VERSION         SUGGESTED SOLUTION\nPrisma Access Agent on Windows     24.0 through 26.2.2   Upgrade to 26.3 or later.\nPrisma Access Agent on macOS                             No action needed.\nPrisma Access Agent on Linux                             No action needed.\nPrisma Access Agent on iOS                               No action needed.\nPrisma Access Agent on Android                           No action needed.\nPrisma Access Agent on Chrome OS                         No action needed.\nAll older unsupported versions                           Upgrade to a supported fixed version.","supportingMedia":[{"type":"text/html","base64":false,"value":"<table class=\"tbl\"><thead><tr><th>Version<br></th><th>Minor Version<br></th><th>Suggested Solution<br></th></tr></thead><tbody><tr>\n                                    <td>Prisma Access Agent on Windows<br></td>\n                                    <td>24.0 through 26.2.2 </td>\n                                    <td>Upgrade to 26.3 or later.</td>\n                                </tr><tr><td>Prisma Access Agent on macOS<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on Linux<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on iOS<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on Android<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on Chrome OS<br></td><td></td><td>No action needed.</td></tr><tr><td>All older unsupported versions<br></td><td>&nbsp;</td><td>Upgrade to a supported fixed version.</td></tr></tbody></table>"}]}],"exploits":[{"lang":"en","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}]}],"timeline":[{"time":"2026-08-12T16:00:00.000Z","lang":"en","value":"Initial publication."}],"credits":[{"lang":"en","value":"Palo Alto Networks thanks Daniel Cuthbert and Vladislav Ovitchinikov from Banco Santander for discovering and reporting this issue.","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-13T13:27:26.711967Z","id":"CVE-2026-0293","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-13T13:27:50.592Z"}}]}}