PT-2026-30912 · Red Hat+1 · Cockpit+1
Florian Kohnhäuser
·
Published
2026-03-23
·
Updated
2026-05-24
·
CVE-2026-4631
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cockpit versions prior to 360
Description
The remote login feature in Cockpit fails to validate or sanitize user-supplied hostnames and usernames passed from the web interface to the SSH client. An attacker with network access to the web service can send a single HTTP request to the login endpoint to inject malicious SSH options or shell commands, such as via
ProxyCommand, leading to remote code execution on the host. This process occurs during the authentication flow before credential verification, allowing the attack to be performed without valid credentials. Approximately 1.3 million services are estimated to be affected worldwide.Recommendations
Update to version 360.
As a temporary workaround, restrict network access to the login endpoint to minimize the risk of exploitation.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cockpit
Rocky Linux