<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Prisma Access Agent (&lt; 26.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/prisma-access-agent--26.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 18:58:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/prisma-access-agent--26.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in Prisma Access Agent for Linux</title><link>https://feed.craftedsignal.io/briefs/2026-09-prisma-access-disclosure/</link><pubDate>Wed, 09 Sep 2026 18:58:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-prisma-access-disclosure/</guid><description>An information disclosure vulnerability in the Prisma Access Agent for Linux allows local, low-privileged users to access sensitive configuration data and stored credentials (CVE-2026-0305).</description><content:encoded><![CDATA[<p>Palo Alto Networks has disclosed an information disclosure vulnerability, identified as CVE-2026-0305, affecting the Prisma Access Agent on Linux. The vulnerability stems from the improper exposure of sensitive data, allowing a local user with low-level privileges to read sensitive configuration files and credentials managed by the agent. This issue impacts all versions of the Prisma Access Agent on Linux prior to 26.3. Versions on macOS, Windows, iOS, Android, and Chrome OS are not affected by this vulnerability. There are no known workarounds, and organizations running Prisma Access Agent on Linux should prioritize upgrading to version 26.3 or later to remediate the exposure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a local attacker to access sensitive configuration details and credentials potentially used by the Prisma Access Agent for authentication. This exposure may provide an attacker with the necessary information to pivot within the network or escalate privileges further, depending on the scope of the exposed credentials. There is no evidence of active exploitation in the wild as of the advisory publication date.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Prisma Access Agent for Linux installations to version 26.3 or later immediately to address CVE-2026-0305.</li>
<li>Audit Linux system configurations to ensure that file permissions for configuration directories are restricted to the minimum required users.</li>
<li>Monitor for suspicious local access patterns or unauthorized attempts to read configuration files located in directories associated with the Prisma Access Agent.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>vulnerability</category><category>information-disclosure</category><category>linux</category><category>dlp-bypass</category><category>endpoint-security</category></item></channel></rss>