Impact
An asset upload endpoint in Cockpit CMS 2.6.0 permits authenticated users to upload files of any type, including executable PHP. The default configuration allows all extensions, and uploaded files are placed in a publicly accessible directory. A malicious user can therefore upload a PHP webshell and run arbitrary operating‑system commands, compromising confidentiality, integrity, and availability of the entire server.
Affected Systems
Vendor Cockpit CMS, Product Cockpit CMS. The vulnerability affects version 2.6.0; no other product versions are listed as affected in the available data.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS data is not available, but because the flaw requires an authenticated account and the upload endpoint is web accessible, an attacker with legitimate credentials can use any network location to upload a malicious file and trigger execution. The vulnerability is not listed in the CISA KEV catalog. In practice the attack is straightforward once a user is logged in, making the risk significant for organizations with open or broadly accessible manager accounts.
OpenCVE Enrichment