Palo Alto Networks Security Advisories / CVE-2026-0303

CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File

Urgency MODERATE

047910
Severity 2.4 · LOW
Exploit Maturity UNREPORTED
Response Effort MODERATE
Recovery USER
Value Density DIFFUSE
Attack Vector LOCAL
Attack Complexity LOW
Attack Requirements NONE
Automatable NO
User Interaction PASSIVE
Product Confidentiality NONE
Product Integrity LOW
Product Availability NONE
Privileges Required NONE
Subsequent Confidentiality HIGH
Subsequent Integrity HIGH
Subsequent Availability HIGH

Description

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. 

Product Status

VersionsAffectedUnaffected
Checkov by Prisma Cloud 3.2.0< 3.2.532>= 3.2.532

Required Configuration for Exposure

No special configuration is required to be vulnerable to this issue.

Severity: LOW, Suggested Urgency: MODERATE

If the user scans infrastructure as code (IaC) files from untrusted sources.
LOW - CVSS-BT: 2.4 /CVSS-B: 6.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue. 

Weakness Type and Impact

CWE-829 Inclusion of Functionality from Untrusted Control Sphere

CAPEC-248 Command Injection

Solution

Version
Minor Version
Suggested Solution
Checkov by Prisma Cloud 3.2
3.2.0 through 3.2.531 Upgrade to 3.2.532or later.

Checkov integration in Prisma Cloud is upgraded automatically when new versions become available.

Workarounds and Mitigations

Until a fixed version is deployed, avoid running Checkov over untrusted content, and pass configuration explicitly via a trusted configuration file rather than allowing configuration to be auto-loaded from the scanned directory.

Acknowledgments

Palo Alto Networks thanks Michael Adedeji for discovering and reporting this issue.

CPE Applicability

Timeline

Initial Publication
© 2026 Palo Alto Networks, Inc. All rights reserved.