Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0302

CVE-2026-0302 release notes and known issues

Checkov by Prisma Cloud: OS Command Injection Vulnerability

Scope: Checkov by Prisma Cloud. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Checkov by Prisma Cloud

Affected versions

  • < 3.2.502

Fixed versions or updates

  • >= 3.2.502

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.501 Upgrade to 3.2.502 or later.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

Checkov by Prisma Cloud: OS Command Injection Vulnerability

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source