PT-2026-36004 · Cockpit · Cockpit Cms

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-34965

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP code through rule parameters which is written directly to server-side PHP files and executed via include() to achieve arbitrary command execution on the underlying server.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-34965

Affected Products

Cockpit Cms