HIGH
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
Published May 13, 2026
7.3
HIGHCVSS 4.0
EPSS 0.15%
Description
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
Affected products
-
- Version 0StatusaffectedConstraints<146.16.6.165
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Palo Alto Networks | Prisma Browser | unaffected |
|
AND
- < 146.16.6.165
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 146.16.6.165 or later.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30062 Advisory
- https://security.paloaltonetworks.com/CVE-2026-0237 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30062 | Advisory | |
| https://security.paloaltonetworks.com/CVE-2026-0237 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published May 13, 2026
Updated May 14, 2026
Reserved Nov 3, 2025
Link CVE-2026-0237
CISA Vulnrichment
Updated May 13, 2026
ENISA EUVD
EUVD-2026-30062 Assigner palo_alto
Published May 13, 2026
Updated May 14, 2026
Exploited since n/a
Link EUVD-2026-30062