CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
Description
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| Checkov by Prisma Cloud 3.2.0 | < 3.2.532 | >= 3.2.532 |
Required Configuration for Exposure
No special configuration is required to be vulnerable to this issue.
Severity: LOW, Suggested Urgency: MODERATE
If the user scans infrastructure as code (IaC) files from untrusted sources.
LOW
- CVSS-BT: 2.4 /CVSS-B: 6.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Weakness Type and Impact
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Solution
| Version | Minor Version | Suggested Solution |
|---|---|---|
| Checkov by Prisma Cloud 3.2 |
3.2.0 through 3.2.531 | Upgrade to 3.2.532or later. |
Checkov integration in Prisma Cloud is upgraded automatically when new versions become available.
Workarounds and Mitigations
Until a fixed version is deployed, avoid running Checkov over untrusted content, and pass configuration explicitly via a trusted configuration file rather than allowing configuration to be auto-loaded from the scanned directory.
Acknowledgments
CPE Applicability
- cpe:2.3:a:palo_alto_networks:checkov_by_prisma_cloud:*:*:*:*:*:*:*:* is vulnerable from (including)3.2.0 and up to (excluding)3.2.532