Impact
Cockpit-files contains a flaw that lets a low‑privileged local user change the ownership of files outside the intended paste destination by creating a symbolic link in a crafted directory and then using the privileged "Paste as owner" feature. This can compromise data integrity and, in some scenarios, weaken confidentiality if the new ownership grants unauthorized read access. The weakness is a classic path traversal and symbolic link dereference issue (CWE‑61).
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 10 and 9 systems that run the cockpit‑files component. Any installation of these distributions that has this component exposed to users is potentially impacted, regardless of version number when the flaw is present.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity risk. The EPSS score is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local user action: the attacker must craft a directory with a symlink that points outside the target and then invoke the privileged paste operation while selecting a different owner. Because the attack is local and interactive, it is unlikely to be automated, but any privileged operation that uses this paste feature could be abused by users with low privileges.
OpenCVE Enrichment