{"id":"CVE-2026-0302","title":"An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.","summary":"An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.","severity":"low","cvss":1.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber","cwe":["CWE-78"],"vendor":"Palo Alto Networks","product":"Checkov by Prisma Cloud","affected":["checkov_by_prisma_cloud >= 3.2.0 < 3.2.502"],"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T14:50:07.813","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0302","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0302","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T13:00:38.190667Z"},"cvssSource":"cna","ingestedAt":"2026-09-13T04:20:46.818Z","epss":0.00824,"epssPercentile":0.55391,"slug":"CVE-2026-0302","body":"## Overview\n\nAn OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":6,"depthScoreParts":{"impact":6.1,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}