Количество 12
Количество 12
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and user ...
openSUSE-SU-2026:20523-1
Security update for cockpit
RLSA-2026:7384
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
RLSA-2026:7383
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
GHSA-rq49-h582-83m7
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
ELSA-2026-7384
ELSA-2026-7384: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL)
ELSA-2026-7383
ELSA-2026-7383: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL)
BDU:2026-05259
Уязвимость системы управления серверами Cockpit, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код
openSUSE-SU-2026:21399-1
Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 9% Низкий | 6 месяцев назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 9% Низкий | 6 месяцев назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 9% Низкий | 6 месяцев назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and user ... | CVSS3: 9.8 | 9% Низкий | 6 месяцев назад | |
openSUSE-SU-2026:20523-1 Security update for cockpit | 9% Низкий | 6 месяцев назад | ||
RLSA-2026:7384 Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection | 9% Низкий | 4 месяца назад | ||
RLSA-2026:7383 Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection | 9% Низкий | 4 месяца назад | ||
GHSA-rq49-h582-83m7 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 9% Низкий | 6 месяцев назад | |
ELSA-2026-7384 ELSA-2026-7384: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL) | 9% Низкий | 6 месяцев назад | ||
ELSA-2026-7383 ELSA-2026-7383: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL) | 9% Низкий | 6 месяцев назад | ||
BDU:2026-05259 Уязвимость системы управления серверами Cockpit, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 9% Низкий | 6 месяцев назад | |
openSUSE-SU-2026:21399-1 Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions | 2 месяца назад |
Уязвимостей на страницу