← volver
CVE-2026-4802highCWE-78

Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8epss 1.0%
de la publicación al arma0 días
Publicada en NVD11 may
1ª PoC11 may
probabilidad de explotación
1.0%top 39% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
PoCs públicas encontradas1
githubgithub.com/hakaioffsec/CVE-2026-48023
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.