{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/checkov-by-prisma-cloud-3.2.0---3.2.501/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:palo_alto_networks:checkov_by_prisma_cloud:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Checkov by Prisma Cloud (3.2.0 - 3.2.501)","Checkov by Prisma Cloud (3.2.0 \u003c= version \u003c 3.2.532)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","command-injection","prisma-cloud","rce","checkov","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Palo Alto Networks"],"content_html":"\u003cp\u003ePalo Alto Networks has disclosed an OS command injection vulnerability (CVE-2026-0302) affecting Checkov by Prisma Cloud versions 3.2.0 through 3.2.501. The vulnerability is classified under CWE-78: Improper Neutralization of Special Elements used in an OS Command. It enables a local, low-privileged user to execute arbitrary commands within the context of the running Checkov process.\u003c/p\u003e\n\u003cp\u003eThe exploitation requires the attacker to influence the input consumed by a Checkov scan. While the vulnerability is classified with a low severity score, successful exploitation leads to high integrity and confidentiality impact on the affected environment. Palo Alto Networks is currently unaware of any active malicious exploitation of this issue. Users are advised to upgrade to version 3.2.502 or later to remediate the vulnerability, as no workarounds are available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local user to execute arbitrary commands with the privileges of the Checkov process. This can lead to unauthorized access to sensitive data, modification of infrastructure-as-code files, or further escalation within the host environment. The impact on confidentiality and integrity is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Checkov by Prisma Cloud to version 3.2.502 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit build pipelines and local scanning workflows that process untrusted configuration files.\u003c/li\u003e\n\u003cli\u003eRestrict access to Checkov execution environments to trusted users only, as the vulnerability requires local access to influence scan inputs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T18:58:23Z","date_published":"2026-09-09T18:57:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-0302-checkov-injection/","summary":"CVE-2026-0302 allows local users with low privileges to achieve OS command injection by influencing input consumed during Checkov scanning processes.","title":"OS Command Injection in Checkov by Prisma Cloud","url":"https://feed.craftedsignal.io/briefs/2026-09-0302-checkov-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Checkov by Prisma Cloud (3.2.0 - 3.2.501)","version":"https://jsonfeed.org/version/1.1"}