---
id: CVE-2008-6954
aliases:
  - GHSA-p8w2-f44p-fmcj
  - PYSEC-2026-795
title: >-
  Cobbler Web Interface Kickstart Template Remote Privilege Escalation
  Vulnerability
summary: >-
  Cobbler Web Interface Kickstart Template Remote Privilege Escalation
  Vulnerability
severity: high
vendor: cobbler
product: cobbler
ecosystem: pip
affected:
  - cobbler < 1.2.9
patched:
  - cobbler 1.2.9
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-p8w2-f44p-fmcj'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2008-6954'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/46625'
  - url: 'https://github.com/cobbler/cobbler'
  - url: >-
      https://web.archive.org/web/20111227125913/http://secunia.com/advisories/32804
  - url: >-
      https://web.archive.org/web/20111227151912/http://secunia.com/advisories/32737
  - url: >-
      https://web.archive.org/web/20200228143518/http://www.securityfocus.com/bid/32317
  - url: >-
      https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00462.html
  - url: >-
      https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00485.html
  - url: 'http://freshmeat.net/projects/cobbler/releases/288374'
tags:
  - osv
  - pip
epss: 0.02163
epssPercentile: 0.81187
ingestedAt: '2026-07-08T18:25:51.735Z'
---

## Overview

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code with the root privileges in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.

## Affected packages

- `cobbler < 1.2.9`

## Remediation

Upgrade to a patched release:

- `cobbler 1.2.9`
