← back
CVE-2026-38992criticalobserved exploitationCWE-94

CVE-2026-38992

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 0.4%
from disclosure to weapon
Published on NVDApr 29
VulnCheck+96d
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
yesVulnCheck
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a