Command Injection Vulnerability in Prowler Kubernetes Provider
CVE-2026-73263
9.9CRITICAL
What is CVE-2026-73263?
A command injection vulnerability exists in the Prowler cloud security platform, affecting versions prior to 5.36.0. The vulnerability arises from the Kubernetes provider's connection test, which incorrectly processes kubeconfig_content containing a legacy GCP auth-provider. This flaw allows an attacker to supply arbitrary commands via config.cmd-path and config.cmd-args, which can then be executed by subprocess.Popen on the shared worker. This issue has been addressed in version 5.36.0, emphasizing the importance of updating to safeguard against potential exploits.
Affected Version(s)
prowler < 5.36.0
