Junglewise Threat Intelligence

CVE-2026-0303: Palo Alto Networks Checkov arbitrary code execution via auto-loaded configuration

CVE-2026-0303 · Severity: info · CVSS 2.4 · Published 2026-09-10

Vendors: Palo Alto Networks.

Executive brief

Checkov by Prisma Cloud is an infrastructure-as-code (IaC) scanning tool used by organizations to validate cloud configurations and detect misconfigurations. The vulnerability allows arbitrary code execution when Checkov processes an attacker-controlled configuration file in a scanned directory, potentially compromising systems that scan untrusted or shared code repositories.

Technical details

This is a code execution vulnerability stemming from untrusted control sphere inclusion (CWE-829). The root cause is Checkov's automatic loading of configuration files from the scanned directory without proper validation. The attack vector is local with low complexity—an attacker places a malicious configuration file in a directory that Checkov will scan, and when invoked without explicit trusted configuration, the tool auto-loads and executes the attacker's code. User interaction is passive (simply running the scan). The attack requires no authentication or special privileges. A patch is available in version 3.2.532 and later; users should upgrade immediately or avoid scanning untrusted content until patched.

Affected products

  • Palo Alto Networks Checkov by Prisma Cloud 3.2.0 through 3.2.531

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fix available in version 3.2.532 and later

References

Related threats