Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0303

CVE-2026-0303 release notes and known issues

Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File

Scope: Checkov by Prisma Cloud. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Checkov by Prisma Cloud

Affected versions

  • < 3.2.532

Fixed versions or updates

  • >= 3.2.532

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.531 Upgrade to 3.2.532or later. Checkov integration in Prisma Cloud is upgraded automatically when new versions become available.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source