Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade cockpit-docUpgrade cockpit-wsUpgrade cockpitUpgrade cockpit-systemUpgrade cockpit-packagekitUpgrade cockpit-storagedUpgrade cockpit-ws-selinuxUpgrade cockpit-bridge | Apr 16, 2026 | Apr 10, 2026 |
| Debian | — | Upgrade cockpit | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade cockpitUpgrade cockpit-storagedUpgrade cockpit-packagekitUpgrade cockpit-ws-selinuxUpgrade cockpit-bridgeUpgrade cockpit-docUpgrade cockpit-systemUpgrade cockpit-ws | Apr 22, 2026 | Apr 7, 2026 |
| Redhat_linux | — | Upgrade cockpit-debugsourceUpgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpit-debuginfoUpgrade cockpitUpgrade cockpit-storagedUpgrade cockpit-wsUpgrade cockpit-ws-selinuxUpgrade cockpit-packagekitUpgrade cockpit-doc | Apr 13, 2026 | Apr 7, 2026 |
| Rocky_linux | — | Upgrade cockpitUpgrade cockpit-ws-selinuxUpgrade cockpit-debuginfoUpgrade cockpit-debugsourceUpgrade cockpit-ws | May 25, 2026 | May 21, 2026 |
| Suse | — | Upgrade cockpit-wsUpgrade cockpit-develUpgrade cockpit-storagedUpgrade cockpit-docUpgrade cockpit-bridgeUpgrade cockpit-kdumpUpgrade cockpit-selinuxUpgrade cockpit-packagekitUpgrade cockpit-ws-selinuxUpgrade cockpit-systemUpgrade cockpitUpgrade cockpit-networkmanagerUpgrade cockpit-firewalld | Apr 23, 2026 | Apr 18, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub