CVE-2026-0268
Description
A local attacker on Linux can bypass VPN enforcement in Prisma Access Agent to route traffic outside the tunnel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A local attacker on Linux can bypass VPN enforcement in Prisma Access Agent to route traffic outside the tunnel.
Vulnerability
A security control bypass vulnerability exists in the Prisma Access Agent for Linux. This issue allows a local attacker to route network traffic outside of the established VPN tunnel. This vulnerability affects Prisma Access Agent versions prior to 26.2.1 on Linux. No special configuration is required for exposure [1].
Exploitation
An attacker with local access and low privileges on a Linux system running a vulnerable Prisma Access Agent can exploit this vulnerability. The attacker needs to be able to execute commands on the system. No user interaction is required, and the attack is automatable [1].
Impact
Successful exploitation allows a local attacker to route network traffic outside the VPN tunnel, potentially bypassing security controls and accessing resources that should be protected. This could lead to a high impact on product confidentiality, as sensitive traffic might be exposed [1].
Mitigation
Prisma Access Agent versions 25.7 through 26.2.0 on Linux are affected. Users should upgrade to Prisma Access Agent version 26.2.1 or later to address this vulnerability. Palo Alto Networks is not aware of any malicious exploitation of this issue [1].
AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Palo Alto Networks: Eight Vulnerabilities Disclosed on June 10, 2026Vypr Intelligence · Jun 10, 2026