Description
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
Published: 2026-09-10
Score: 1.1 Low
EPSS: n/a
KEV: No
Impact: Command Execution
Action: Patch
AI Analysis

Impact

The vulnerability is an OS command injection flaw in Palo Alto Networks Checkov by Prisma Cloud. A local user can supply input that is executed directly by the Checkov process, enabling arbitrary command execution, which could lead to unauthorized code execution, data exfiltration, or system compromise.

Affected Systems

Vendor: Palo Alto Networks. Product: Checkov by Prisma Cloud. Versions 3.2.0 through 3.2.501 are vulnerable. Version 3.2.502 and later contain the fix.

Risk and Exploitability

With a CVSS score of 1.1 the technical impact is assessed as low and no exploit data is currently available. The EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, indicating limited exploitation evidence. The CVE description indicates that a local user can execute arbitrary commands, so the likely attack vector is local access. While the risk is modest, the ability to run arbitrary commands makes the flaw potentially dangerous if the local user account is compromised or privileges are not strictly controlled.

Generated by OpenCVE AI on September 10, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Checkov to version 3.2.502 or later.
  • Restrict Checkov runtime privileges to trusted administrators and limit local user access.
  • Deploy Checkov in a sandboxed or containerized environment to isolate any injected commands from the host system.

Generated by OpenCVE AI on September 10, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
Title Checkov by Prisma Cloud: OS Command Injection Vulnerability
First Time appeared Palo Alto Networks
Palo Alto Networks checkov By Prisma Cloud
Weaknesses CWE-78
CPEs cpe:2.3:a:palo_alto_networks:checkov_by_prisma_cloud:*:*:*:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks checkov By Prisma Cloud
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Checkov By Prisma Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-09-10T06:05:20.011Z

Reserved: 2025-11-03T20:45:00.329Z

Link: CVE-2026-0302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T07:17:00.843

Modified: 2026-09-10T07:17:00.843

Link: CVE-2026-0302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:30:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')