CVE-2026-105217: fallo de gravedad baja en cockpit-hq cockpit
Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php
Publicada el · Actualizada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.3epss 0.1%
probabilidad de explotación
0.1%top 99% de las CVE
explotación observada
noninguna fuente lo reporta
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
cockpit-hq · cockpitCVEs relacionadas — cockpit-hq cockpit
En el mismo producto, de las más peligrosas a las menos.
Referencias
https://github.com/Cockpit-HQ/Cockpithttps://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/cron.php#L70-L102https://github.com/Cockpit-HQ/Cockpit/commit/c611492adc17362578faa97f9c30b41e6c16e040https://github.com/Cockpit-HQ/Cockpit/issues/318https://www.vulncheck.com/advisories/cockpit-cms-2.12.0-before-2.14.1-disabled-tls-verification-via-cron-php