Skip to content
palo-alto-networksCVE-2026-0303

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

Low2.4CVE-2026-0303 · Published Sep 10, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Checkov by Prisma Cloud
Vendor
>= 3.2.0, < 3.2.5323.2.532
Details and references

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Severity from
no source yet
Weakness
CWE-829

More palo-alto-networks advisories

All
DateAdvisory
Sep 10An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials.
CVE-2026-0305Medium4.3fixed in Prisma Access Agent 26.2
Sep 10A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and...
CVE-2026-0306Medium5.8fixed in Prisma Access Agent 26.2
Sep 10Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS...
CVE-2026-0307Medium5.9fixed in GlobalProtect App 6.3.3-h15, GlobalProtect App 6.0.15, GlobalProtect App 6.3.3-h15
Sep 10A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web...
CVE-2026-0308Low1.1fixed in PAN-OS 12.1.10, PAN-OS 11.2.13-h2, PAN-OS 11.1.16-h2
Sep 10A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user.
CVE-2026-0309Medium4.0fixed in PAN-OS 12.2.3, PAN-OS 12.1.4-h10, PAN-OS 11.2.4-h21
Sep 10A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane...
CVE-2026-0310High7.2fixed in PAN-OS 12.2.3, PAN-OS 12.1.4-h10, PAN-OS 11.2.4-h21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.