<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:palo_alto_networks:checkov_by_prisma_cloud:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apalo_alto_networkscheckov_by_prisma_cloud/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 18:57:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apalo_alto_networkscheckov_by_prisma_cloud/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in Checkov by Prisma Cloud</title><link>https://feed.craftedsignal.io/briefs/2026-09-0302-checkov-injection/</link><pubDate>Wed, 09 Sep 2026 18:57:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-0302-checkov-injection/</guid><description>CVE-2026-0302 allows local users with low privileges to achieve OS command injection by influencing input consumed during Checkov scanning processes.</description><content:encoded><![CDATA[<p>Palo Alto Networks has disclosed an OS command injection vulnerability (CVE-2026-0302) affecting Checkov by Prisma Cloud versions 3.2.0 through 3.2.501. The vulnerability is classified under CWE-78: Improper Neutralization of Special Elements used in an OS Command. It enables a local, low-privileged user to execute arbitrary commands within the context of the running Checkov process.</p>
<p>The exploitation requires the attacker to influence the input consumed by a Checkov scan. While the vulnerability is classified with a low severity score, successful exploitation leads to high integrity and confidentiality impact on the affected environment. Palo Alto Networks is currently unaware of any active malicious exploitation of this issue. Users are advised to upgrade to version 3.2.502 or later to remediate the vulnerability, as no workarounds are available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a local user to execute arbitrary commands with the privileges of the Checkov process. This can lead to unauthorized access to sensitive data, modification of infrastructure-as-code files, or further escalation within the host environment. The impact on confidentiality and integrity is high.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Checkov by Prisma Cloud to version 3.2.502 or later immediately.</li>
<li>Audit build pipelines and local scanning workflows that process untrusted configuration files.</li>
<li>Restrict access to Checkov execution environments to trusted users only, as the vulnerability requires local access to influence scan inputs.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>vulnerability</category><category>command-injection</category><category>prisma-cloud</category><category>rce</category><category>checkov</category><category>supply-chain</category></item></channel></rss>