CVE-2026-0278: Prisma Access Agent DLP Bypass on Windows (CVSS 7.8)
A local user on Windows can circumvent data loss prevention (DLP) controls in Palo Alto Networks' Prisma Access Agent by exploiting multiple protection mechanism failures. An attacker with local access can bypass the DLP policies meant to prevent sensitive data from leaving the system. This vulnerability requires local access and does not affect the macOS version of Prisma Access Agent.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-693
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-07-09 / 2026-07-16
NVD description (verbatim)
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-0278 involves multiple protection mechanism failures in the Prisma Access Agent DLP component on Windows, classified under CWE-693 (Protection Mechanism Failure). The vulnerability allows a local, authenticated user to bypass DLP policy enforcement controls without user interaction. The attack has high impact on confidentiality, integrity, and availability (CVSS 3.1 vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, score 7.8). The macOS variant of Prisma Access Agent is explicitly unaffected.
Business impact
Organizations relying on Prisma Access Agent's DLP capabilities on Windows may experience data exfiltration if a user with local system access exploits this vulnerability. Sensitive data—financial records, intellectual property, personal information—could bypass intended protection controls. Compliance obligations (GDPR, HIPAA, CCPA) may be violated if DLP systems fail to contain data as designed. Affected organizations face potential data breach notification costs, regulatory fines, and reputational harm.
Affected systems
Vulnerable systems include Windows endpoints running Palo Alto Networks Prisma Access Agent. macOS deployments are not affected. The scope is limited to Windows; organizations with macOS-only or hybrid deployments (where Windows endpoints are unaffected) face lower risk. Determine which Windows devices are enrolled in Prisma Access Agent and what sensitivity of data flows through them to assess exposure.
Exploitability
Exploitation requires local user access with at least basic privileges—an insider, compromised account, or attacker with initial endpoint foothold. No network access, special configuration, or user interaction is required once local access is established. Attack complexity is low, making it straightforward for an attacker to execute once they have a foothold. This is a critical concern for environments with high user turnover, shared systems, or elevated insider threat risks.
Remediation
Apply a vendor security update for Palo Alto Networks Prisma Access Agent on all affected Windows systems. Verify patch availability and version applicability against the Palo Alto Networks advisory. Until patched, restrict local administrative privileges and monitor for suspicious data access patterns. Consider enforcing endpoint detection and response (EDR) tooling to detect anomalous DLP bypass attempts or data staging behavior.
Patch guidance
Check Palo Alto Networks' official security advisory for patched Prisma Access Agent versions. Apply patches to Windows endpoints through your standard deployment pipeline (endpoint management tools, group policy, or vendor patch mechanisms). Test patches in a pre-production environment before broad rollout, especially if Prisma Access Agent is critical to your data protection strategy. Prioritize Windows systems handling high-risk data. Verify after patching that DLP policies are functioning as expected.
Detection guidance
Monitor Windows event logs and Prisma Access Agent logs for unusual data access or file operations originating from privileged local users. Flag attempts to access, copy, or move sensitive files to non-protected locations or external media. Monitor for process execution patterns that suggest DLP policy circumvention (e.g., alternate data paths, API calls that bypass normal channels). EDR solutions should alert on suspicious local file operations or privilege escalation followed by data operations. Network monitoring may not detect local bypass attempts, so endpoint-level visibility is essential.
Why prioritize this
This vulnerability scores 7.8 (HIGH CVSS 3.1) due to high confidentiality, integrity, and availability impact combined with low attack complexity and local access requirements. While it requires local presence, the consequence—complete bypass of DLP controls—directly threatens the security controls organizations rely on to prevent data loss. Organizations using Prisma Access Agent for DLP on Windows should patch urgently. Priority should be higher for systems handling regulated or highly sensitive data.
Risk score, explained
CVSS 3.1 score of 7.8 reflects: (1) Attack Vector Local—requires local access, limiting blast radius but not irrelevant given insider and compromise scenarios; (2) Attack Complexity Low—no special conditions or tricks needed; (3) Privileges Required Low—standard user permissions suffice; (4) User Interaction None—no social engineering or user action needed; (5) Scope Unchanged—impact confined to the system; (6) Confidentiality, Integrity, Availability High—the DLP mechanism itself is compromised, allowing data exfiltration, modification, and potential system impact. The HIGH severity is warranted given DLP's role in data protection strategy.
Frequently asked questions
Does this affect our macOS Prisma Access Agent deployments?
No. Palo Alto Networks has explicitly stated that macOS deployments of Prisma Access Agent are not affected by CVE-2026-0278. Only Windows systems are vulnerable.
What exactly can an attacker do if they exploit this?
An attacker with local access can bypass the DLP policies that normally prevent data from leaving the system. This means they can exfiltrate sensitive data, move it to unprotected locations, or send it outside the organization—all without triggering DLP alerts or blocks that would normally stop such activity.
Is there an exploit available in the wild?
As of the advisory date, CVE-2026-0278 is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog. However, absence from the KEV list does not guarantee the vulnerability is not being exploited; always assume active threats are possible and prioritize patching accordingly.
How should we prioritize patching this if we have hundreds of Windows systems?
Focus first on Windows endpoints that process or store high-value data (finance, HR, R&D, customer records, regulated data). Then patch general-purpose systems. Consider using automated endpoint management tools to deploy patches at scale. Test the patch in a pilot group before broad deployment to ensure compatibility with your environment.
This analysis is based on published vulnerability data as of July 2026. Patch availability, version numbers, and vendor timelines should be verified directly against Palo Alto Networks' official security advisory and your vendor's release notes. No exploit code or weaponized proof-of-concept is provided. Organizations should conduct their own risk assessment based on their Windows Prisma Access Agent deployment footprint and data sensitivity. This is informational only and does not constitute security advice tailored to your environment. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-11248HIGHChrome Navigation Bypass in Google Lens
- CVE-2026-12031HIGHChrome Sandbox Escape on Windows – Patch Guidance
- CVE-2026-45588HIGHWindows Secure Boot Protection Mechanism Failure – HIGH Severity
- CVE-2026-45656HIGHWindows UEFI Protection Mechanism Bypass (CVSS 7.8)
- CVE-2026-47656HIGHWindows Boot Manager Protection Bypass – High Severity Patch Advisory
- CVE-2026-48568HIGHWindows Secure Boot Protection Bypass (CVSS 7.9 HIGH)
- CVE-2026-48570HIGHWindows Secure Boot Protection Mechanism Bypass
- CVE-2026-48575HIGHWindows Secure Boot Protection Mechanism Failure – HIGH Severity