PT-2026-35924 · Cockpit · Cockpit

Felsec

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-38992

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cockpit versions prior to 2.13.6
Description Arbitrary code execution is possible via the filter parameter within multiple endpoints. This allows an attacker to execute system commands on the underlying infrastructure by utilizing the MongoLite $func operator.
Recommendations Update to a version later than 2.13.5. Restrict the use of the filter parameter in affected endpoints as a temporary mitigation measure.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38992
GHSA-FM6C-RHCF-7439

Affected Products

Cockpit