CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-0291

lowcovered by 2 sourcesfirst seen 2026-08-12
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

CSIRTS triage

What
Authenticated user can delete limited files on Linux systems running Prisma Access Agent.
Who is affected
Linux systems running Prisma Access Agent with authenticated users.
Urgency
Low urgency due to requirement for authentication and limited scope of impact.
Action
Apply Palo Alto Networks patch for Prisma Access Agent CVE-2026-0291.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-0291

Get an email if CVE-2026-0291 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-0291

CVE.org record

Embed the live status

CVE-2026-0291 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-0291 status](https://www.csirts.com/badge/CVE-2026-0291)](https://www.csirts.com/cve/CVE-2026-0291)