PT-2026-35934 · Cockpit · Cockpit

Felsec

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-38991

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cockpit versions prior to 2.13.6
Description A misconfiguration in the Bucket component isFileTypeAllowed() function allows an authenticated attacker to bypass an extension filter using a specially crafted filename. This enables the renaming of arbitrary files to have a .php extension, which can lead to arbitrary code execution on the underlying server.
Recommendations Update to a version later than 2.13.5. As a temporary workaround, restrict access to the Bucket component or the isFileTypeAllowed() function to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-38991

Affected Products

Cockpit