PT-2026-30912 · Red Hat+1 · Cockpit+1

Florian Kohnhäuser

·

Published

2026-03-23

·

Updated

2026-05-24

·

CVE-2026-4631

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cockpit versions prior to 360
Description The remote login feature in Cockpit fails to validate or sanitize user-supplied hostnames and usernames passed from the web interface to the SSH client. An attacker with network access to the web service can send a single HTTP request to the login endpoint to inject malicious SSH options or shell commands, such as via ProxyCommand, leading to remote code execution on the host. This process occurs during the authentication flow before credential verification, allowing the attack to be performed without valid credentials. Approximately 1.3 million services are estimated to be affected worldwide.
Recommendations Update to version 360. As a temporary workaround, restrict network access to the login endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

ALSA-2026:7383
ALSA-2026:7384
BDU:2026-05259
CVE-2026-4631
OPENSUSE-SU-2026:10531-1
OPENSUSE-SU-2026:20523-1
RHSA-2026:7381
RHSA-2026:7382
RHSA-2026:7383
RHSA-2026:7384
SUSE-SU-2026:21106-1
SUSE-SU-2026:21184-1

Affected Products

Cockpit
Rocky Linux