cockpit-machines vulnerabilities
CVEs whose affected-version data names the cockpit-machines package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-92768Medium· 5.5PoCA flaw was found in cockpit-machines
A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or inst…
CVE-2026-92747Medium· 5.0PoCA flaw was found in `cockpit-machines`
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This …
CVE-2026-92745Medium· 5.0A flaw was found in cockpit-machines
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is p…