CVE-2026-0303
PoC largeArbitrary Code Execution in Palo Alto Networks Checkov via Malicious Config File
CVE-2026-0303 is a code execution flaw in Checkov, Palo Alto Networks' open-source Infrastructure-as-Code scanner sold as part of Prisma Cloud, arising from functionality being included from an untrusted control sphere (CWE-829). It is triggered when Checkov scans a directory containing an attacker-controlled configuration file, for example a cloned third-party repository or downloaded module, and the attack requires local access plus user interaction, which is why the CVSS 4.0 base score is low (2.4) despite code execution impact. An attacker who plants the malicious file gains arbitrary code execution in the context of the scanning process, typically a developer workstation or CI/CD runner, and the scoring's high impact on subsequent systems suggests compromise could propagate to pipelines and infrastructure reachable from that machine. Anyone running Checkov against directories containing untrusted content is affected, while teams scanning only trusted internal repositories face little practical risk; the provided data includes no affected or fixed version numbers. There are no reports of in-the-wild exploitation (not in CISA KEV, and exploitation is scored as unreported), but a public proof-of-concept is available on GitHub.
What to do: Check the Palo Alto Networks security advisory for the patched Checkov release and upgrade the standalone CLI or Prisma Cloud-bundled scanner when a fixed version is published, since no version numbers were provided in this data. Until then, avoid running Checkov on untrusted repositories or modules, or confine such scans to sandboxed CI jobs with minimal credentials. Review whether your pipelines scan third-party code and consult the public PoC (github.com/YonLiud/CVE-2026-0303) to validate exposure safely.
| Palo Alto Networks Checkov (Prisma Cloud Infrastructure-as-Code scanner) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
- Weakness
- CWE-829
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
In the news0 stories
No ingested article mentions this CVE yet.