PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73264 prowler-cloud CVE debrief

CVE-2026-73264 is a high-severity vulnerability in Prowler, a cloud security platform, allowing authenticated users with Lighthouse provider configuration access to send outbound requests with an API key to attacker-controlled or internal endpoints. This issue, fixed in version 5.33.1, could lead to unauthorized disclosure and lateral movement. Defenders should verify exposure and prioritize remediation, focusing on Prowler instances with Lighthouse provider configuration access. The vulnerability involves supplying an unvalidated base_url for the openai_compatible provider through specific API endpoints, potentially impacting cloud security posture.

Vendor
prowler-cloud
Product
prowler
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-09
Advisory published
2026-08-12
Advisory updated
2026-09-09

Who should care

Defenders responsible for Prowler instances, especially those with Lighthouse provider configuration access, should assess exposure and prioritize remediation. This includes verifying instance versions, restricting access, and monitoring for suspicious activity. Security teams managing cloud security posture and vulnerability management processes should also review and address this vulnerability promptly.

Why it matters

CVE-2026-73264 is a high-severity vulnerability in Prowler that allows an authenticated user to send outbound requests with an API key to attacker-controlled or internal endpoints, potentially leading to unauthorized disclosure and lateral movement.

  • Potential unauthorized disclosure of API key
  • Possible lateral movement to internal endpoints
  • Required verification of Prowler instance version and exposure
  • Potential impact on cloud security posture

Technical summary

CVE-2026-73264 is a high-severity vulnerability in Prowler, a cloud security platform. An authenticated user with Lighthouse provider configuration access can supply an unvalidated base_url for the openai_compatible provider, causing outbound requests with the API key to be sent to attacker-controlled or internal endpoints. This issue is fixed in version 5.33.1 and could lead to unauthorized disclosure and lateral movement within cloud environments. The vulnerability involves specific API endpoints: POST /api/v1/lighthouse/providers and POST /api/v1/lighthouse/providers/{id}/connection.

Defensive priority

Defenders should prioritize verifying exposure and remediating vulnerable Prowler instances, especially those with Lighthouse provider configuration access.

Recommended defensive actions

  • Verify Prowler instance version and exposure to Lighthouse provider configuration access
  • Remediate vulnerable instances by upgrading to version 5.33.1 or later
  • Monitor for suspicious outbound requests from Prowler instances
  • Review and restrict Lighthouse provider configuration access
  • Perform compensating controls review for exposed systems
  • Conduct asset inventory of Prowler instances
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the scope of affected versions and potential impact require further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73264 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73264

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73264 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73264

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.