<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:25:32.778725+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21468</id>
    <title>ALSA-2026:21468 — Important: cockpit security update</title>
    <updated>2026-10-03T09:25:33.179641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: cockpit, AlmaLinux:9: cockpit-bridge, AlmaLinux:9: cockpit-doc, AlmaLinux:9: cockpit-packagekit, AlmaLinux:9: cockpit-storaged, AlmaLinux:9: cockpit-system, AlmaLinux:9: cockpit-ws, AlmaLinux:9: cockpit-ws-selinux</p>
<p>Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.</p>
<p>Security Fix(es):</p>
<p>* cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI (CVE-2026-4802)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337197</id>
    <title>EUVD-2026-337197</title>
    <updated>2026-10-03T09:25:33.179715+00:00</updated>
    <content>EUVD-2026-337197</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4802</id>
    <title>fkie_cve-2026-4802</title>
    <updated>2026-10-03T09:25:33.179732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3wjm-5g86-c6p3</id>
    <title>GHSA-3wjm-5g86-c6p3</title>
    <updated>2026-10-03T09:25:33.179757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3wjm-5g86-c6p3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2907</id>
    <title>OESA-2026-2907 — cockpit security update</title>
    <updated>2026-10-03T09:25:33.179773+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: cockpit</p>
<p>Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.

Security Fix(es):</p>
<p>A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)</p>
<p>A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10819-1</id>
    <title>openSUSE-SU-2026:10819-1 — cockpit-361-1.1 on GA media</title>
    <updated>2026-10-03T09:25:33.179804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cockpit-361-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10819-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21390</id>
    <title>RHSA-2026:21390 — Red Hat Security Advisory: cockpit security update</title>
    <updated>2026-10-03T09:25:33.179821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21390"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21468</id>
    <title>RLSA-2026:21468 — Important: cockpit security update</title>
    <updated>2026-10-03T09:25:33.179836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: cockpit</p>
<p>Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.</p>
<p>Security Fix(es):</p>
<p>* cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI (CVE-2026-4802)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2005-1</id>
    <title>SUSE-SU-2026:2005-1 — Security update for cockpit</title>
    <updated>2026-10-03T09:25:33.179857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for cockpit</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2005-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4802</id>
    <title>UBUNTU-CVE-2026-4802</title>
    <updated>2026-10-03T09:25:33.179872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: cockpit, Ubuntu:20.04:LTS: cockpit, Ubuntu:22.04:LTS: cockpit, Ubuntu:24.04:LTS: cockpit, Ubuntu:25.10: cockpit, Ubuntu:26.04:LTS: cockpit</p>
<p>A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1699</id>
    <title>WID-SEC-W-2026-1699 — Red Hat Enterprise Linux (Cockpit): Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-03T09:25:33.179898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (Cockpit) ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1699"/>
  </entry>
</feed>
