PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-4631

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
red hat enterprise linux 10red hat enterprise linux 10.0 extended update supportred hat enterprise linux 9red hat enterprise linux 9.6 extended update supportred hat enterprise linux 7red hat enterprise linux 8
Updated Sep 18, 2026View on NVD →
S4E scanner

Cockpit Web Console < 360 - Remote Code Execution

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. References: https://github.com/cockpit-project/cockpit/security/advisories/GHSA-m4gv-x78h-3427 https://github.com/cockpit-project/cockpit/commit/9d0695647 https://github.com/allisonkarlitskaya/ferny/commit/44ec511c99 Remediation: Update to the latest version with input validation and sanitization for SSH parameters.

Used 3.2k times · domain, subdomain, ipv4

CVE history: red hat enterprise linux 10

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →