PatchSiren

prowler-cloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH prowler-cloud CVE published 2026-08-12

CVE-2026-73264

CVE-2026-73264 is a high-severity vulnerability in Prowler, a cloud security platform, allowing authenticated users with Lighthouse provider configuration access to send outbound requests with an API key to attacker-controlled or internal endpoints. This issue, fixed in version 5.33.1, could lead to unauthorized disclosure and lateral movement. Defenders should verify exposure and prioritize remediation, [truncated]

CRITICAL prowler-cloud CVE published 2026-08-12

CVE-2026-73263

A critical vulnerability was found in Prowler, a cloud security platform, which could allow an attacker to execute arbitrary commands on the shared worker through a legacy GCP auth-provider in kubeconfig_content. This issue was fixed in version 5.36.0. The vulnerability existed in the Kubernetes provider connection test, which accepted kubeconfig_content containing a legacy gcp auth-provider with config.c [truncated]

MEDIUM prowler-cloud CVE published 2026-08-12

CVE-2026-73262

CVE-2026-73262 is a medium-severity vulnerability in Prowler, a cloud security platform. Prior to version 5.37.0, Prowler's HTML output formatter did not properly escape user-supplied resource tags, allowing a cloud principal with modify permissions to inject HTML or JavaScript that would execute when another user opened the report. This issue was fixed in version 5.37.0.

CRITICAL prowler-cloud CVE published 2026-07-10

CVE-2026-59151

CVE-2026-59151 is a critical vulnerability in Prowler, a cloud security platform, that affects its SAML authentication flow. Prior to version 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token. The ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of bindi [truncated]