Description
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Arbitrary File Ownership Change
Action: Apply Patch
AI Analysis

Impact

Cockpit-files contains a flaw that lets a low‑privileged local user change the ownership of files outside the intended paste destination by creating a symbolic link in a crafted directory and then using the privileged "Paste as owner" feature. This can compromise data integrity and, in some scenarios, weaken confidentiality if the new ownership grants unauthorized read access. The weakness is a classic path traversal and symbolic link dereference issue (CWE‑61).

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 10 and 9 systems that run the cockpit‑files component. Any installation of these distributions that has this component exposed to users is potentially impacted, regardless of version number when the flaw is present.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity risk. The EPSS score is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local user action: the attacker must craft a directory with a symlink that points outside the target and then invoke the privileged paste operation while selecting a different owner. Because the attack is local and interactive, it is unlikely to be automated, but any privileged operation that uses this paste feature could be abused by users with low privileges.

Generated by OpenCVE AI on September 19, 2026 at 11:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update cockpit‑files to a fixed version released by Red Hat
  • Restrict the "Paste as owner" function to privileged users only, or disable it for low‑privilege accounts
  • Enforce file system permissions that prevent low‑privilege users from creating symbolic links or changing ownership in paste target directories

Generated by OpenCVE AI on September 19, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
Title Cockpit-files: cockpit-files: arbitrary file ownership change via symlink following in privileged paste
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-61
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T15:28:45.417Z

Reserved: 2026-09-14T21:58:42.731Z

Link: CVE-2026-91202

cve-icon Vulnrichment

Updated: 2026-09-22T15:27:37.111Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:29.260

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-91202

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T16:33:00Z

Links: CVE-2026-91202 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:49Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following