No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prowler-cloud
Prowler-cloud prowler |
|
| Vendors & Products |
Prowler-cloud
Prowler-cloud prowler |
Wed, 12 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST /api/v1/providers/{id}/connection loaded it through config.load_kube_config_from_dict in prowler/providers/kubernetes/kubernetes_provider.py, causing kubernetes-python CommandTokenSource.token to run the attacker-supplied command through subprocess.Popen on the shared worker. This issue is fixed in version 5.36.0. | |
| Title | Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T15:14:28.454Z
Reserved: 2026-08-11T17:18:01.599Z
Link: CVE-2026-73263
Updated: 2026-08-12T15:13:25.671Z
Status : Received
Published: 2026-08-12T15:18:30.943
Modified: 2026-08-12T16:17:21.910
Link: CVE-2026-73263
No data.
OpenCVE Enrichment
Updated: 2026-08-12T19:00:07Z