cockpit-files vulnerabilities
CVEs whose affected-version data names the cockpit-files package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-91205Medium· 6.0A flaw was found in cockpit-files
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory…
CVE-2026-91203Medium· 6.0PoCA flaw was found in cockpit-files
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating…
CVE-2026-91202Medium· 6.1A flaw was found in cockpit-files
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary…