Inclusion of Functionality from Untrusted Control Sphere in Checkov by Prisma Cloud - CVE-2026-0303
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper validation when Checkov scans a directory that contains an attacker-controlled configuration file. A remote attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.