Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:7383

Опубликовано: 21 мая 2026
Источник: rocky
Оценка: Critical

Описание

Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection

Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.

Security Fix(es):

  • cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
cockpit-docnoarch3.el10_1.rocky.0.1cockpit-doc-344-3.el10_1.rocky.0.1.noarch.rpm
cockpit-wsx86_643.el10_1.rocky.0.1cockpit-ws-344-3.el10_1.rocky.0.1.x86_64.rpm
cockpit-ws-selinuxx86_643.el10_1.rocky.0.1cockpit-ws-selinux-344-3.el10_1.rocky.0.1.x86_64.rpm
cockpit-bridgenoarch3.el10_1.rocky.0.1cockpit-bridge-344-3.el10_1.rocky.0.1.noarch.rpm
cockpit-systemnoarch3.el10_1.rocky.0.1cockpit-system-344-3.el10_1.rocky.0.1.noarch.rpm
cockpitx86_643.el10_1.rocky.0.1cockpit-344-3.el10_1.rocky.0.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

CVSS3: 9.8
redhat
4 месяца назад

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

CVSS3: 9.8
nvd
4 месяца назад

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

CVSS3: 9.8
debian
4 месяца назад

Cockpit's remote login feature passes user-supplied hostnames and user ...

suse-cvrf
4 месяца назад

Security update for cockpit