← voltar
CVE-2026-92747mediumCWE-214

Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 5epss 0.2%
probabilidade de exploração
0.2%top 95% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N