Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4802

Опубликовано: 11 мая 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

Отчет

An Important arbitrary command execution flaw exists in Cockpit's system logs UI. This vulnerability allows a remote attacker to execute arbitrary commands on the host by exploiting unsanitized user-controlled parameters within crafted links. This impacts Red Hat Enterprise Linux systems where Cockpit is installed and accessible.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Operational risk reduction until fixes are available: restrict access to Cockpit to trusted networks/users only, and avoid opening untrusted crafted Cockpit URLs

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7cockpitNot affected
Red Hat Enterprise Linux 10cockpitFixedRHSA-2026:2167628.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportcockpitFixedRHSA-2026:2139027.05.2026
Red Hat Enterprise Linux 8cockpitFixedRHSA-2026:2170028.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportcockpitFixedRHSA-2026:2151627.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicecockpitFixedRHSA-2026:2151627.05.2026
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionscockpitFixedRHSA-2026:2151627.05.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicecockpitFixedRHSA-2026:2151527.05.2026
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionscockpitFixedRHSA-2026:2151527.05.2026
Red Hat Enterprise Linux 9cockpitFixedRHSA-2026:2146827.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2451155cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI

EPSS

Процентиль: 60%
0.01016
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
nvd
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
debian
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attack ...

suse-cvrf
около 1 месяца назад

Security update for cockpit

rocky
2 месяца назад

Important: cockpit security update

EPSS

Процентиль: 60%
0.01016
Низкий

8 High

CVSS3

Уязвимость CVE-2026-4802