Command Injection Vulnerability in Prowler Kubernetes Provider
CVE-2026-73263

9.9CRITICAL

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73263?

A command injection vulnerability exists in the Prowler cloud security platform, affecting versions prior to 5.36.0. The vulnerability arises from the Kubernetes provider's connection test, which incorrectly processes kubeconfig_content containing a legacy GCP auth-provider. This flaw allows an attacker to supply arbitrary commands via config.cmd-path and config.cmd-args, which can then be executed by subprocess.Popen on the shared worker. This issue has been addressed in version 5.36.0, emphasizing the importance of updating to safeguard against potential exploits.

Affected Version(s)

prowler < 5.36.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.