OS Command Injection in Checkov by Prisma Cloud - CVE-2026-0302

 

OS Command Injection in Checkov by Prisma Cloud - CVE-2026-0302

Published: September 14, 2026


Vulnerability identifier: #VU149474
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0302
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the processes running Checkov. A local user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Checkov by Prisma Cloud

How to mitigate CVE-2026-0302

Install updates from vendor's website.

Checkov by Prisma Cloud - update to 3.2.502

External References

Related Security Bulletins