CVE-2026-0292
Last modified
CVE-2026-0292 is a medium-severity vulnerability rated 6/10 on the CVSS scale. An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Prisma Access Agent | < 26.3 |
References
- https://security.paloaltonetworks.com/CVE-2026-0292Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-0292?
How severe is CVE-2026-0292?
How do I fix CVE-2026-0292?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-0286A command injection vulnerability in the management plane of…7.2
- CVE-2026-0287Multiple denial of service vulnerabilities in Palo Alto Netw…7.5
- CVE-2026-0288Multiple buffer overflow vulnerabilities in the User-ID Term…7.5
- CVE-2026-0289A security bypass vulnerability in the Account Protection f…6.5
- CVE-2026-0290An information disclosure vulnerability in the Account Prote…5.5
- CVE-2026-0291An improper link resolution before file access vulnerability…4.4
- CVE-2026-0293A vulnerability in Palo Alto Networks Prisma® Access Agent o…6
- CVE-2026-0294A privilege escalation (PE) vulnerability in the Palo Alto N…7.8
- CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ cl…7
- CVE-2026-0296Improper certificate validation vulnerabilities in Palo Alto…7.4
- CVE-2026-0297A buffer overflow vulnerability exists in the Palo Alto Netw…8.1
- CVE-2026-0298An improper input validation vulnerability exists in the Win…8.1
Are you affected by CVE-2026-0292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
