OS Command Injection Vulnerability in Palo Alto Networks Checkov
CVE-2026-0302

1.1LOW

Key Information:

Vendor
CVE Published:
10 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-0302?

An OS command injection vulnerability exists in Palo Alto Networks Checkov that allows a local user to execute arbitrary commands within the processes running Checkov. This could potentially lead to unauthorized access or manipulation of the system, highlighting the need for prompt remediation to safeguard against exploitation.

Affected Version(s)

Checkov by Prisma Cloud 3.2.0 < 3.2.502

References

CVSS V4

Score:
1.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Gherasim
.