VulnSea

Cockpit vulnerabilities

CVEs whose affected-version data names the Cockpit package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-105217Low· 3.1
4d ago

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can p…

▾ Sunlitcockpit-hq · cockpitEPSS 0.10%via NVD
CVE-2026-91149High· 7.5
2w ago

A flaw was found in Cockpit

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded nu…

▾ TwilightRed Hat · cockpitEPSS 0.35%via NVD
CVE-2026-91147Medium· 5.9PoC
2w ago

A flaw was found in `cockpit-ws`

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made t…

▾ TwilightRed Hat · cockpitEPSS 0.40%via NVD
CVE-2026-91142Low· 3.6
2w ago

A flaw was found in Cockpit

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileg…

▾ SunlitRed Hat · cockpitEPSS 0.13%via NVD
CVE-2026-82449Medium· 5.3
1mo ago

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which acc…

▾ Sunlitcockpit-hq · cockpitEPSS 0.42%via NVD
CVE-2026-23695Medium· 5.4
4mo ago

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function usin…

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function usin…

▾ SunlitCockpit-HQ · CockpitEPSS 0.14%via NVD
Cockpit vulnerabilities (CVEs) · VulnSea