CVE-2026-73263Exploit

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST /api/v1/providers/{id}/connection loaded it through config.load_kube_config_from_dict in prowler/providers/kubernetes/kubernetes_provider.py, causing kubernetes-python CommandTokenSource.token to run the attacker-supplied command through subprocess.Popen on the shared worker. This issue is fixed in version 5.36.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-12: 2PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification2 categories
Exploit
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit available 🔴 CRITICAL: CVE-2026-73263 (prowler-cloud/prowler) AAS 12.7 — exploit available 🔴 CRITICAL: CVE-2026-73300 (budibase/budibase) AAS 12.7 — exploit available + 2 more CRITICAL 30 vulnerabilities — CRITICAL: 7, HIGH: 23 Full bulletin: https://aretiq.ai/bulletins/2026-08-12/

    Post summary

    The bulletin announces multiple critical CVEs, noting PoC availability for one and exploit availability for several others, with no mention of active exploitation or patches.

    00094526
    232 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    ⚠️ Command Execution Vulnerability Discovered in Prowler (CVE-2026-73263) A flaw in Prowler (< 5.36.0) allows attackers to achieve arbitrary command execution on shared worker nodes during Kubernetes provider connection tests. ⚙️ How it works: By supplying a malicious kubeconfig with legacy GCP auth-provider configurations (cmd-path / cmd-args), the system bypasses validation checks and executes attacker-controlled commands via subprocess.Popen. 🛡️ Fix: Upgrade to Prowler v5.36.0 or later immediately.

    Post summary

    CVE-2026-73263 permits arbitrary command execution on Prowler instances by exploiting malicious kubeconfig files; users should immediately upgrade to version 5.36.0 or newer.

    0000080
    288 followersView on X

Explore more