cve-2026-38992
CRITICAL CVSS 9.8 opencve
Description
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
Timeline
- Published
- 2026-04-29 15:16 UTC
- Last Modified
- 2026-06-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
opencve | ||
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
vulnrichment |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"advisories": [
{
"id": "GHSA-fm6c-rhcf-7439",
"source": "ghsa",
"title": "Cockpit is vulnerable to arbitrary code execution",
"url": "https://github.com/advisories/GHSA-fm6c-rhcf-7439"
}
],
"cve": "CVE-2026-38992",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[0,2.13.5]"
}
}
],
"enrichment": {
"confidence": 80.0,
"confidence_source": "inferred",
"scores": [
{
"score": 80.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "n/a",
"source": "cna",
"vendor": "n/a"
},
"product": "cockpit",
"vendor": "cockpit-hq"
}
],
"created": "2026-04-29T15:30:13.918428+00:00",
"title": "Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator",
"updated": "2026-05-02T00:45:30.298434+00:00",
"vendors": [
"cockpit-hq",
"cockpit-hq$PRODUCT$cockpit"
]
},
"epss": {
"score": 0.00726
},
"mitre": {
"cpes": [],
"created": "2026-04-29T00:00:00+00:00",
"description": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/38xxx/CVE-2026-38992.json",
"references": [
"https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
"https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
],
"title": null,
"updated": "2026-04-30T15:22:49.472000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [],
"created": "2026-04-29T15:16:05.750000+00:00",
"description": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-38992.json",
"references": [
"https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
"https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
],
"title": null,
"updated": "2026-06-17T10:41:49.460000+00:00",
"vendors": [],
"weaknesses": [
"CWE-94"
]
},
"opencve": {
"changes": [
{
"created": "2026-04-29T14:45:00+00:00",
"data": [
{
"details": {
"new": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
"old": null
},
"type": "description"
},
{
"details": {
"added": [
"https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
"https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
],
"removed": []
},
"type": "references"
}
],
"id": "a2bc59cc-e917-47ac-a99e-35268b5924a7"
},
{
"created": "2026-04-29T15:45:00+00:00",
"data": [
{
"details": [
"cockpit-hq",
"cockpit-hq$PRODUCT$cockpit"
],
"type": "first_time"
},
{
"details": {
"added": [
"cockpit-hq",
"cockpit-hq$PRODUCT$cockpit"
],
"removed": []
},
"type": "vendors"
}
],
"id": "3b4dcae2-3a02-4f74-874f-511301830838"
},
{
"created": "2026-04-29T17:30:00+00:00",
"data": [
{
"details": {
"new": "Arbitrary Code Execution in Cockpit CMS via Filter Parameter",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-78",
"CWE-94"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "fb67812d-b8e9-4d0b-a680-a73d44d0b4e8"
},
{
"created": "2026-04-30T16:30:00+00:00",
"data": [
{
"details": {
"added": {
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "poc",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "e84bbc2c-ef01-45dc-832a-8eb3644d17db"
},
{
"created": "2026-05-01T06:00:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Arbitrary Code Execution in Cockpit CMS via Filter Parameter"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-78"
]
},
"type": "weaknesses"
}
],
"id": "5de41e75-9cea-4226-aa58-f2e19467ac8c"
},
{
"created": "2026-05-02T01:00:00+00:00",
"data": [
{
"details": {
"new": "Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator",
"old": null
},
"type": "title"
}
],
"id": "f94b6d40-5056-4f3f-908b-1a34925e1b8f"
}
],
"cpes": {
"data": [],
"providers": []
},
"created": {
"data": "2026-04-29T00:00:00+00:00",
"provider": "mitre"
},
"description": {
"data": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "vulnrichment"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00726
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "yes",
"Exploitation": "poc",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/",
"https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0"
],
"providers": [
"mitre",
"nvd",
"vulnrichment"
]
},
"title": {
"data": "Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator",
"provider": "enrichment"
},
"updated": {
"data": "2026-05-02T00:45:30.298434+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"cockpit-hq",
"cockpit-hq$PRODUCT$cockpit"
],
"providers": [
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-94"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-04-29T00:00:00+00:00",
"description": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "poc",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [
"https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/"
],
"title": null,
"updated": "2026-04-30T13:03:39.426000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/38xxx/CVE-2026-38992.json",
"weaknesses": [
"CWE-94"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)