{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/prisma-access-agent--26.2-on-windows/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Prisma Access Agent (\u003c 26.3)","Prisma Access Agent (\u003c 26.2 on Windows)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","information-disclosure","linux","dlp-bypass","endpoint-security"],"_cs_type":"threat","_cs_vendors":["Palo Alto Networks"],"content_html":"\u003cp\u003ePalo Alto Networks has disclosed an information disclosure vulnerability, identified as CVE-2026-0305, affecting the Prisma Access Agent on Linux. The vulnerability stems from the improper exposure of sensitive data, allowing a local user with low-level privileges to read sensitive configuration files and credentials managed by the agent. This issue impacts all versions of the Prisma Access Agent on Linux prior to 26.3. Versions on macOS, Windows, iOS, Android, and Chrome OS are not affected by this vulnerability. There are no known workarounds, and organizations running Prisma Access Agent on Linux should prioritize upgrading to version 26.3 or later to remediate the exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to access sensitive configuration details and credentials potentially used by the Prisma Access Agent for authentication. This exposure may provide an attacker with the necessary information to pivot within the network or escalate privileges further, depending on the scope of the exposed credentials. There is no evidence of active exploitation in the wild as of the advisory publication date.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Prisma Access Agent for Linux installations to version 26.3 or later immediately to address CVE-2026-0305.\u003c/li\u003e\n\u003cli\u003eAudit Linux system configurations to ensure that file permissions for configuration directories are restricted to the minimum required users.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious local access patterns or unauthorized attempts to read configuration files located in directories associated with the Prisma Access Agent.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T18:58:30Z","date_published":"2026-09-09T18:58:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-prisma-access-disclosure/","summary":"An information disclosure vulnerability in the Prisma Access Agent for Linux allows local, low-privileged users to access sensitive configuration data and stored credentials (CVE-2026-0305).","title":"Information Disclosure Vulnerability in Prisma Access Agent for Linux","url":"https://feed.craftedsignal.io/briefs/2026-09-prisma-access-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Prisma Access Agent (\u003c 26.2 on Windows)","version":"https://jsonfeed.org/version/1.1"}