PT-2026-39595 · Cockpit+1 · Cockpit+1

Gabriel Rodrigues

+1

·

Published

2026-05-11

·

Updated

2026-06-11

·

CVE-2026-4802

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cockpit (affected versions not specified)
Description A flaw in the system logs user interface (UI) allows a remote attacker to achieve arbitrary command execution on the host. The issue stems from unsanitized user-controlled parameters within crafted links, which enable the injection of shell metacharacters and command substitutions. This can lead to the execution of arbitrary shell commands and potential complete system compromise. Exploitation requires the user to be logged in to Cockpit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21468
ALSA-2026:21676
ALSA-2026:21700
CVE-2026-4802
OPENSUSE-SU-2026:10819-1
RHSA-2026:21390
RHSA-2026:21392
RHSA-2026:21394
RHSA-2026:21395
RHSA-2026:21468
RHSA-2026:21515
RHSA-2026:21516
RHSA-2026:21647
RHSA-2026:21676
RHSA-2026:21700
SUSE-SU-2026:2363-1

Affected Products

Cockpit
Rocky Linux