PT-2026-35934 · Cockpit · Cockpit

Felsec

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-38991

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cockpit versions prior to 2.13.6
Description A misconfiguration in the Bucket component isFileTypeAllowed() function allows an authenticated attacker to bypass an extension filter using a specially crafted filename. This enables the renaming of arbitrary files to have a .php extension, which can lead to arbitrary code execution on the underlying server.
Recommendations Update to a version later than 2.13.5. As a temporary workaround, restrict access to the Bucket component or the isFileTypeAllowed() function to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38991
GHSA-J2RX-4JG9-79MW

Affected Products

Cockpit