Inclusion of Functionality from Untrusted Control Sphere in Checkov by Prisma Cloud - CVE-2026-0303

 

Inclusion of Functionality from Untrusted Control Sphere in Checkov by Prisma Cloud - CVE-2026-0303

Published: September 14, 2026


Vulnerability identifier: #VU149475
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0303
CWE-ID: CWE-829
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper validation when Checkov scans a directory that contains an attacker-controlled configuration file. A remote attacker can execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Checkov by Prisma Cloud

How to mitigate CVE-2026-0303

Install updates from vendor's website.

Checkov by Prisma Cloud - update to 3.2.532

External References

Related Security Bulletins