PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 18, 2025

Cobbler 'XML-RPC' - Authentication Bypass

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.6k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cobblerby cobbler
>= 3.0.0, < 3.2.3
cobblerby cobbler_project
AFFECTED< 3.2.3SAFE ✓≥ 3.2.3
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Cobbler 'XML-RPC' - Authentication Bypass CVE-2024-47533 Scanner | S4E