SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-0306

MEDIUM · CVSS 5.8 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of the Prisma Access Agent allows local users on affected platforms (Palo Alto, Linux, Android, and Chrome) to bypass DLP policy controls, potentially leading to unauthorized exfiltration of sensitive data. Organizations utilizing these platforms should prioritize addressing this issue to mitigate the risk of data breaches. Users on macOS, iOS, and Chrome OS are not impacted by this vulnerability.

CVE
CVE-2026-0306
Severity
MEDIUM
CVSS
5.8
EPSS
0.10%
Palo Alto Linux Android Chrome

Original NVD Description

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.