CVE-2026-0302

Checkov by Prisma Cloud: OS Command Injection Vulnerability

Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.008
55.9th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 10, 2026
Assigned by palo_alto

Description

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Cloud Cloud Security cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Checkov by Prisma Cloud

Credit

George Gherasim

Vendor remediation

Version Minor Version Suggested Solution Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.501 Upgrade to 3.2.502 or later.

Something wrong here?