VYPR
Medium severityNVD Advisory· Published May 13, 2026· Updated May 14, 2026

CVE-2026-0246

CVE-2026-0246

Description

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.

The Prisma Access Agent on iOS, Android and Chrome OS are not affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local non-admin users can escalate to root/SYSTEM in Palo Alto Networks Prisma Access Agent prior to version 26.2.1, enabling code execution and data access.

The vulnerability is a missing authorization (CWE-862) in the privilege management mechanism of the Prisma Access Agent. A locally authenticated non-administrative user can bypass authorization checks and escalate privileges to root on macOS/Linux or NT AUTHORITY\SYSTEM on Windows [1].

Exploitation requires only local access with a low-privileged user account; no user interaction or special configuration is needed. Attack complexity is low, and the attack vector is local [1].

Successful exploitation allows the attacker to execute arbitrary code and read sensitive information that is normally accessible only to privileged accounts. The CVSSv4.0 base score is 8.5, reflecting high impacts on confidentiality, integrity, and availability [1].

Palo Alto Networks has released version 26.2.1 for affected platforms (macOS, Linux, Windows). Users should upgrade to mitigate this vulnerability. iOS, Android, and Chrome OS versions are not affected. No malicious exploitation has been reported [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.