Unvalidated Base URL Vulnerability in Prowler Cloud Security Platform
CVE-2026-73264

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73264?

Prior to version 5.33.1, Prowler, a cloud security platform, exposed a vulnerability that allowed authenticated users with specific Lighthouse provider configuration access to provide an unvalidated 'base_url' for the openai_compatible provider. This occurred through the POST requests to /api/v1/lighthouse/providers and /api/v1/lighthouse/providers/{id}/connection. Consequently, the system could perform outbound API calls that included sensitive authorization details, like the API key, directed towards endpoints controlled by potential attackers or internal systems, thus heightening the risk of unauthorized access and data leakage.

Affected Version(s)

prowler < 5.33.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.