CVE-2026-4802

EUVD-2026-29051
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60.04%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:356.2-1.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:334.2-1.el10_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:310.8-1.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:264.3-1.el8_6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service
0:264.3-1.el8_6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions
0:264.3-1.el8_6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:286.2-1.el8_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:286.2-1.el8_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:356.2-1.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions
0:264.3-1.el9_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:286.3-1.el9_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
0:311.3-1.el9_4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:334.3-1.el9_6 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
cockpit
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
forky
365-1
fixed
sid
365-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cockpit
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
cockpit
RHEL 8
0:310.8-1.el8_10
fixed
RHEL 8.6 AUS
0:264.3-1.el8_6
fixed
RHEL 8.6 E4S
0:264.3-1.el8_6
fixed
RHEL 8.6 TUS
0:264.3-1.el8_6
fixed
RHEL 8.8 E4S
0:286.2-1.el8_8
fixed
RHEL 8.8 TUS
0:286.2-1.el8_8
fixed
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-bridge
RHEL 8
0:310.8-1.el8_10
fixed
RHEL 8.6 AUS
0:264.3-1.el8_6
fixed
RHEL 8.6 E4S
0:264.3-1.el8_6
fixed
RHEL 8.6 TUS
0:264.3-1.el8_6
fixed
RHEL 8.8 E4S
0:286.2-1.el8_8
fixed
RHEL 8.8 TUS
0:286.2-1.el8_8
fixed
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-doc
RHEL 8
0:310.8-1.el8_10
fixed
RHEL 8.6 AUS
0:264.3-1.el8_6
fixed
RHEL 8.6 E4S
0:264.3-1.el8_6
fixed
RHEL 8.6 TUS
0:264.3-1.el8_6
fixed
RHEL 8.8 E4S
0:286.2-1.el8_8
fixed
RHEL 8.8 TUS
0:286.2-1.el8_8
fixed
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-packagekit
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-storaged
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-system
RHEL 8
0:310.8-1.el8_10
fixed
RHEL 8.6 AUS
0:264.3-1.el8_6
fixed
RHEL 8.6 E4S
0:264.3-1.el8_6
fixed
RHEL 8.6 TUS
0:264.3-1.el8_6
fixed
RHEL 8.8 E4S
0:286.2-1.el8_8
fixed
RHEL 8.8 TUS
0:286.2-1.el8_8
fixed
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-ws
RHEL 8
0:310.8-1.el8_10
fixed
RHEL 8.6 AUS
0:264.3-1.el8_6
fixed
RHEL 8.6 E4S
0:264.3-1.el8_6
fixed
RHEL 8.6 TUS
0:264.3-1.el8_6
fixed
RHEL 8.8 E4S
0:286.2-1.el8_8
fixed
RHEL 8.8 TUS
0:286.2-1.el8_8
fixed
RHEL 9
0:356.2-1.el9_8
fixed
cockpit-ws-selinux
RHEL 9
0:356.2-1.el9_8
fixed