CVE-2026-4631

EUVD-2026-19814
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96.53%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:344-3.el10_1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:334.1-3.el10_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:344-2.el9_7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:334.2-2.el9_6 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
cockpit
bookworm
287.1-0+deb12u3
fixed
bookworm (security)
287.1-0+deb12u2
fixed
bullseye
239-1
fixed
forky
365-1
fixed
sid
365-1
fixed
trixie
337-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cockpit
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
cockpit
RHEL 9
0:344-2.el9_7
fixed
cockpit-bridge
RHEL 9
0:344-2.el9_7
fixed
cockpit-doc
RHEL 9
0:344-2.el9_7
fixed
cockpit-packagekit
RHEL 9
0:344-2.el9_7
fixed
cockpit-storaged
RHEL 9
0:344-2.el9_7
fixed
cockpit-system
RHEL 9
0:344-2.el9_7
fixed
cockpit-ws
RHEL 9
0:344-2.el9_7
fixed
cockpit-ws-selinux
RHEL 9
0:344-2.el9_7
fixed