Threat Advisory

Prowler Vulnerability Delivers Code by Misusing Configuration Attributes

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A stored cross-site scripting vulnerability in prowler and prowler-cloud, identified as CVE-2026-73262 with a CVSS score of 5.4, exists in Prowler's HTML output formatter due to the insertion of unescaped cloud resource tags into generated reports. An attacker who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag, allowing them to read and modify the report DOM, alter displayed findings, and interact with any same-origin local or hosted report content available to the browser when another user opens the generated Prowler HTML report. This vulnerability can undermine trust in generated security findings and expose data contained in the report page. The flaw is classified as a stored cross-site scripting vulnerability, with a network attack vector and user interaction required for exploitation, potentially impacting the integrity and confidentiality of sensitive information contained in security reports.

RECOMMENDATIONS:

  • We recommend you to update prowler and prowler-cloud to below version:
  • https://github.com/prowler-cloud/prowler/releases

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A stored cross-site scripting vulnerability in prowler and prowler-cloud, identified as CVE-2026-73262 with a CVSS score of 5.4, exists in Prowler's HTML output formatter due to the insertion of unescaped cloud resource tags into generated reports. An attacker who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag, allowing them to read and modify the report DOM, alter displayed findings, and interact with any same-origin local or hosted report content available to the browser when another user opens the generated Prowler HTML report. This vulnerability can undermine trust in generated security findings and expose data contained in the report page. The flaw is classified as a stored cross-site scripting vulnerability, with a network attack vector and user interaction required for exploitation, potentially impacting the integrity and confidentiality of sensitive information contained in security reports.

RECOMMENDATIONS:

  • We recommend you to update prowler and prowler-cloud to below version:
  • https://github.com/prowler-cloud/prowler/releases

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu