Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade cockpit-wsUpgrade cockpit-systemUpgrade cockpitUpgrade cockpit-docUpgrade cockpit-storagedUpgrade cockpit-ws-selinuxUpgrade cockpit-packagekitUpgrade cockpit-bridge | Apr 16, 2026 | Apr 10, 2026 |
| Debian | — | Upgrade cockpit | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade cockpit-bridgeUpgrade cockpit-systemUpgrade cockpit-docUpgrade cockpit-ws-selinuxUpgrade cockpit-storagedUpgrade cockpit-wsUpgrade cockpit-packagekitUpgrade cockpit | Apr 22, 2026 | Apr 7, 2026 |
| Redhat_linux | — | Upgrade cockpit-debugsourceUpgrade cockpit-systemUpgrade cockpitUpgrade cockpit-wsUpgrade cockpit-ws-selinuxUpgrade cockpit-bridgeUpgrade cockpit-packagekitUpgrade cockpit-storagedUpgrade cockpit-debuginfoUpgrade cockpit-doc | Apr 13, 2026 | Apr 7, 2026 |
| Rocky_linux | — | Upgrade cockpitUpgrade cockpit-ws-selinuxUpgrade cockpit-debugsourceUpgrade cockpit-debuginfoUpgrade cockpit-ws | May 25, 2026 | May 21, 2026 |
| Suse | — | Upgrade cockpit-docUpgrade cockpit-storagedUpgrade cockpit-wsUpgrade cockpit-develUpgrade cockpit-bridgeUpgrade cockpit-firewalldUpgrade cockpit-kdumpUpgrade cockpit-networkmanagerUpgrade cockpitUpgrade cockpit-selinuxUpgrade cockpit-packagekitUpgrade cockpit-ws-selinuxUpgrade cockpit-system | Apr 23, 2026 | Apr 18, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub