PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 16, 2026

Cockpit Web Console < 360 - Remote Code Execution

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Red Hat Enterprise Linux 10by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 10.0 Extended Update Supportby Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 9by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 9by Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.