Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-38993

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

A flaw was found in Cockpit. This vulnerability, identified as a directory traversal, allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite existing assets with malicious versions. The exploitation occurs via the Buckets component. This could lead to unauthorized modification of data and potential system compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cockpitNot affected
Red Hat Enterprise Linux 7cockpitNot affected
Red Hat Enterprise Linux 8cockpitNot affected
Red Hat Enterprise Linux 9cockpitNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2463843Cockpit: Cockpit: Arbitrary file write via directory traversal in Buckets component

EPSS

Процентиль: 54%
0.00836
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

CVSS3: 6.5
github
3 месяца назад

Cockpit is vulnerable to directory traversal

EPSS

Процентиль: 54%
0.00836
Низкий

8.1 High

CVSS3