Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjp7-qvjx-36p7

Опубликовано: 13 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.9
CVSS3: 7.8

Описание

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.

The Prisma Access Agent on iOS, Android and Chrome OS are not affected.

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.

The Prisma Access Agent on iOS, Android and Chrome OS are not affected.

EPSS

Процентиль: 4%
0.00147
Низкий

5.9 Medium

CVSS4

7.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.8
nvd
3 месяца назад

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts. The Prisma Access Agent on iOS, Android and Chrome OS are not affected.

CVSS3: 7.8
fstec
3 месяца назад

Уязвимость агента удаленного доступа пользователей к корпоративным ресурсам и приложениям Prisma Access Agent, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии, получить доступ на чтение данных и выполнить произвольный код

EPSS

Процентиль: 4%
0.00147
Низкий

5.9 Medium

CVSS4

7.8 High

CVSS3

Дефекты

CWE-862