Checkov IaC Scanner RCE via attackercontrolled config file
CVE-2026-0303 Published on September 10, 2026

Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-0303 can be exploited with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
PASSIVE

Timeline

Initial Publication

Weakness Type

Inclusion of Functionality from Untrusted Control Sphere

The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.


Products Associated with CVE-2026-0303

Want to know whenever a new CVE is published for Palo Alto Networks Checkov By Prisma Cloud? stack.watch will email you.

 

Affected Versions

Palo Alto Networks Checkov by Prisma Cloud: