CVE-2026-0302: Checkov by Prisma Cloud: OS Command Injection Vulnerability (Severity: LOW)
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.2.502 - Upgrade
Upgrade
Palo Alto Networks Checkov by Prisma Cloudto a version that resolves this vulnerability.Fixed in 3.2.502
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running Palo Alto Networks Checkov by Prisma Cloud are exposed where a local user can interact with the Checkov process. The vulnerability is described as enabling command execution in processes running Checkov.
What level of access and interaction does exploitation require?
The supplied severity vector indicates local attack access, low attack complexity, low privileges required, and user interaction. It does not describe the specific user action or input path required.
What could a successful attacker do?
A successful attacker could execute arbitrary operating-system commands in the context of processes running Checkov. The vector indicates impacts to the confidentiality, integrity, and availability of subsequent systems are high, while direct confidentiality and availability impact to the vulnerable system is not indicated.