CVE-2026-0291: CWE-59 Improper Link Resolution Before File Access ('Link Following') in Palo Alto Networks Prisma Access Agent
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-0291) is classified as CWE-59 (Improper Link Resolution Before File Access). It affects the Prisma Access Agent specifically on Linux platforms. The flaw allows a local user with low privileges to exploit symbolic link handling to delete system files within a limited scope, which can lead to disabling the Prisma Access Agent. The vulnerability does not affect other operating system versions of the agent. The CVSS 4.0 base score is 1.1, indicating low severity. No known exploits are reported in the wild, and no vendor advisory or patch information is currently available.
Potential Impact
A local low privileged user on a Linux system running the Prisma Access Agent can delete certain system files, which may disable the agent. The impact is limited in scope and does not allow remote exploitation or privilege escalation beyond the local user context. The vulnerability does not affect other operating systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user access to systems running the Prisma Access Agent on Linux to trusted users only. Monitor for updates from Palo Alto Networks regarding patches or workarounds.
CVE-2026-0291: CWE-59 Improper Link Resolution Before File Access ('Link Following') in Palo Alto Networks Prisma Access Agent
Description
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
CVSS v4.0
Score 1.1low
Affected software
Palo Alto Networks
Prisma Access Agent
Palo Alto Networks
Prisma Access Agent
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-0291) is classified as CWE-59 (Improper Link Resolution Before File Access). It affects the Prisma Access Agent specifically on Linux platforms. The flaw allows a local user with low privileges to exploit symbolic link handling to delete system files within a limited scope, which can lead to disabling the Prisma Access Agent. The vulnerability does not affect other operating system versions of the agent. The CVSS 4.0 base score is 1.1, indicating low severity. No known exploits are reported in the wild, and no vendor advisory or patch information is currently available.
Potential Impact
A local low privileged user on a Linux system running the Prisma Access Agent can delete certain system files, which may disable the agent. The impact is limited in scope and does not allow remote exploitation or privilege escalation beyond the local user context. The vulnerability does not affect other operating systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user access to systems running the Prisma Access Agent on Linux to trusted users only. Monitor for updates from Palo Alto Networks regarding patches or workarounds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- palo_alto
- Date Reserved
- 2025-11-03T20:44:48.974Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7d2ee9bf8831d5398db860
Added to database: 08/13/2026, 02:41:45 UTC
Last enriched: 08/13/2026, 03:01:13 UTC
Last updated: 09/25/2026, 13:47:42 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.