Code Execution Vulnerability in Palo Alto Networks Checkov
CVE-2026-0303

2.4LOW

Key Information:

Vendor
CVE Published:
10 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-0303?

Palo Alto Networks Checkov is susceptible to a code execution vulnerability that enables an attacker to execute arbitrary code when the tool scans a directory containing a configuration file under their control. This flaw can expose systems to potential threats, making it crucial for users to assess their configurations and update their Checkov installations.

Affected Version(s)

Checkov by Prisma Cloud 3.2.0 < 3.2.532

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Adedeji
.