Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-73263: Prowler: Unauthorized Access via Misconfigured Kubernetes Settings
CVE-2026-73263 · published 23 days ago
Summary
A security issue in Prowler's Kubernetes provider allows an attacker to execute commands on the system if they have access to a misconfigured Kubernetes configuration file. This could potentially allow unauthorized access to sensitive data. Update to version 5.36.0 or later to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| prowler-cloud | prowler | < 5.36.0 |
Original advisory text
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-...
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST /api/v1/providers/{id}/connection loaded it through config.load_kube_config_from_dict in prowler/providers/kubernetes/kubernetes_provider.py, causing kubernetes-python CommandTokenSource.token to run the attacker-supplied command through subprocess.Popen on the shared worker. This issue is fixed in version 5.36.0.
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Monitor software like this
Free during beta