Description
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
Published: 2026-04-29
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Cockpit CMS versions before 2.14.0 permits an attacker to inject code through the filter parameter of several endpoints. The injected value is evaluated by the MongoLite database using the $func operator, which can invoke arbitrary system commands. This vulnerability leads directly to uncontrolled code execution on the underlying host, exposing the full confidentiality, integrity, and availability of the server. The weakness aligns with command and code injection issues such as CWE‑94.

Affected Systems

The security issue affects Cockpit CMS releases 2.13.5 and earlier. Any installation running those versions exposes the vulnerable endpoints. The official advisory lists the affected release as 2.13.5 and the new release 2.14.0 that includes the fix.

Risk and Exploitability

With a CVSS score of 9.8 and an EPSS score of < 1%, the vulnerability is rated as critical, but the low exploitation probability indicates that active exploitation is currently rare. However, because the flaw allows arbitrary command execution and is exposed over network endpoints, it remains a high‑risk issue for any organization that runs affected versions. The lack of KEV listing does not reduce the urgency, as the flaw is clearly exploitable regardless of current exploit availability.

Generated by OpenCVE AI on May 2, 2026 at 00:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cockpit CMS to version 2.14.0 or later, which contains the fix for the MongoLite filter parameter processing.
  • If an immediate upgrade is not possible, restrict network access to the affected endpoints, ensuring only trusted internal hosts can reach them.
  • As a temporary measure, ensure that the application runs with the least privilege necessary and consider disabling the $func operator if it is not required for your configuration.

Generated by OpenCVE AI on May 2, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fm6c-rhcf-7439 Cockpit is vulnerable to arbitrary code execution
History

Sat, 02 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Cockpit CMS Arbitrary Code Execution via MongoLite $func Operator

Fri, 01 May 2026 06:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution in Cockpit CMS via Filter Parameter
Weaknesses CWE-78

Thu, 30 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution in Cockpit CMS via Filter Parameter
Weaknesses CWE-78
CWE-94

Wed, 29 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cockpit-hq
Cockpit-hq cockpit
Vendors & Products Cockpit-hq
Cockpit-hq cockpit

Wed, 29 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
Description Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
References

Subscriptions

Cockpit-hq Cockpit
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-30T15:22:49.472Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38992

cve-icon Vulnrichment

Updated: 2026-04-30T13:03:39.426Z

cve-icon NVD

Status : Deferred

Published: 2026-04-29T15:16:05.750

Modified: 2026-04-30T16:16:43.683

Link: CVE-2026-38992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T00:45:30Z

Weaknesses