cve-2026-38992

CRITICAL CVSS 9.8 opencve
Description

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.

Timeline
Published
2026-04-29 15:16 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H nvd
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H opencve
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H vulnrichment
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "GHSA-fm6c-rhcf-7439",
      "source": "ghsa",
      "title": "Cockpit is vulnerable to arbitrary code execution",
      "url": "https://github.com/advisories/GHSA-fm6c-rhcf-7439"
    }
  ],
  "cve": "CVE-2026-38992",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[0,2.13.5]"
            }
          }
        ],
        "enrichment": {
          "confidence": 80.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 80.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "n/a",
          "source": "cna",
          "vendor": "n/a"
        },
        "product": "cockpit",
        "vendor": "cockpit-hq"
      }
    ],
    "created": "2026-04-29T15:30:13.918428+00:00",
    "title": "Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator",
    "updated": "2026-05-02T00:45:30.298434+00:00",
    "vendors": [
      "cockpit-hq",
      "cockpit-hq$PRODUCT$cockpit"
    ]
  },
  "epss": {
    "score": 0.00726
  },
  "mitre": {
    "cpes": [],
    "created": "2026-04-29T00:00:00+00:00",
    "description": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/38xxx/CVE-2026-38992.json",
    "references": [
      "https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
      "https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
    ],
    "title": null,
    "updated": "2026-04-30T15:22:49.472000+00:00",
    "vendors": [],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [],
    "created": "2026-04-29T15:16:05.750000+00:00",
    "description": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-38992.json",
    "references": [
      "https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
      "https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
    ],
    "title": null,
    "updated": "2026-06-17T10:41:49.460000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-94"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-04-29T14:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "added": [
                "https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
                "https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
              ],
              "removed": []
            },
            "type": "references"
          }
        ],
        "id": "a2bc59cc-e917-47ac-a99e-35268b5924a7"
      },
      {
        "created": "2026-04-29T15:45:00+00:00",
        "data": [
          {
            "details": [
              "cockpit-hq",
              "cockpit-hq$PRODUCT$cockpit"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cockpit-hq",
                "cockpit-hq$PRODUCT$cockpit"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "3b4dcae2-3a02-4f74-874f-511301830838"
      },
      {
        "created": "2026-04-29T17:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "Arbitrary Code Execution in Cockpit CMS via Filter Parameter",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-78",
                "CWE-94"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "fb67812d-b8e9-4d0b-a680-a73d44d0b4e8"
      },
      {
        "created": "2026-04-30T16:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 9.8,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "poc",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "e84bbc2c-ef01-45dc-832a-8eb3644d17db"
      },
      {
        "created": "2026-05-01T06:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Arbitrary Code Execution in Cockpit CMS via Filter Parameter"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-78"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "5de41e75-9cea-4226-aa58-f2e19467ac8c"
      },
      {
        "created": "2026-05-02T01:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "f94b6d40-5056-4f3f-908b-1a34925e1b8f"
      }
    ],
    "cpes": {
      "data": [],
      "providers": []
    },
    "created": {
      "data": "2026-04-29T00:00:00+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 9.8,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "vulnrichment"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00726
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "poc",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
        "https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
      ],
      "providers": [
        "mitre",
        "nvd",
        "vulnrichment"
      ]
    },
    "title": {
      "data": "Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-05-02T00:45:30.298434+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "cockpit-hq",
        "cockpit-hq$PRODUCT$cockpit"
      ],
      "providers": [
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-94"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-04-29T00:00:00+00:00",
    "description": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "poc",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [
      "https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/"
    ],
    "title": null,
    "updated": "2026-04-30T13:03:39.426000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/38xxx/CVE-2026-38992.json",
    "weaknesses": [
      "CWE-94"
    ]
  }
}
Enrichment data
View JSON API Download JSON