Palo Alto Networks Checkov OS Command Injection Allows Local User Execution
CVE-2026-0302 Published on September 10, 2026
Checkov by Prisma Cloud: OS Command Injection Vulnerability
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
Vulnerability Analysis
CVE-2026-0302 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Timeline
Initial Publication
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-0302 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-0302
Want to know whenever a new CVE is published for Palo Alto Networks Checkov By Prisma Cloud? stack.watch will email you.
Affected Versions
Palo Alto Networks Checkov by Prisma Cloud:- Version 3.2.0 and below 3.2.502 is affected.