---
id: CVE-2026-23695
title: >-
  Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a
  stored cross-site scripting vulnerability in the Set field type's Display
  template option, where the template string is processed by the $interpolate
  function usin…
summary: >-
  Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a
  stored cross-site scripting vulnerability in the Set field type's Display
  template option, where the template string is processed by the $interpolate
  function usin…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: Cockpit-HQ
product: Cockpit
affected:
  - Cockpit <= 2.14.0
published: '2026-05-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:11.600'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23695'
references:
  - url: >-
      https://github.com/Cockpit-HQ/Cockpit/commit/72a83fcfe85ad8330e9ae834bc02fa517b5749e9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cockpit-cms-stored-xss-via-set-field-display-template
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-15T17:39:34.371151Z'
epss: 0.00138
epssPercentile: 0.02734
ingestedAt: '2026-10-08T16:52:14.680Z'
---

## Overview

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive without sanitization. An attacker with content/:models/manage permission can inject arbitrary JavaScript into the Display template, which executes in the browser of any user viewing the collection items list.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
