A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.
This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0268 |
|
History
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Title | Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux | |
| First Time appeared |
Palo Alto Networks
Palo Alto Networks prisma Access Agent |
|
| Weaknesses | CWE-424 | |
| CPEs | cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:Linux:*:* | |
| Vendors & Products |
Palo Alto Networks
Palo Alto Networks prisma Access Agent |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2026-06-10T20:40:11.198Z
Reserved: 2025-11-03T20:44:28.362Z
Link: CVE-2026-0268
No data.
Status : Received
Published: 2026-06-10T22:16:53.413
Modified: 2026-06-10T22:16:53.413
Link: CVE-2026-0268
No data.
OpenCVE Enrichment
Updated: 2026-06-10T23:15:28Z
Weaknesses