<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:26:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:21468 — Important: cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:21468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: cockpit, AlmaLinux:9: cockpit-bridge, AlmaLinux:9: cockpit-doc, AlmaLinux:9: cockpit-packagekit, AlmaLinux:9: cockpit-storaged, AlmaLinux:9: cockpit-system, AlmaLinux:9: cockpit-ws, AlmaLinux:9: cockpit-ws-selinux&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI (CVE-2026-4802)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: cockpit, AlmaLinux:9: cockpit-bridge, AlmaLinux:9: cockpit-doc, AlmaLinux:9: cockpit-packagekit, AlmaLinux:9: cockpit-storaged, AlmaLinux:9: cockpit-system, AlmaLinux:9: cockpit-ws, AlmaLinux:9: cockpit-ws-selinux&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI (CVE-2026-4802)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:21468</guid>
    </item>
    <item>
      <title>EUVD-2026-337197</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337197</link>
      <description>EUVD-2026-337197</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337197</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4802</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4802</link>
      <description>&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4802</guid>
    </item>
    <item>
      <title>GHSA-3wjm-5g86-c6p3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wjm-5g86-c6p3</link>
      <description>&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wjm-5g86-c6p3</guid>
    </item>
    <item>
      <title>OESA-2026-2907 — cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2907</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10819-1 — cockpit-361-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10819-1</link>
      <description>&lt;p&gt;cockpit-361-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cockpit-361-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10819-1</guid>
    </item>
    <item>
      <title>RHSA-2026:21390 — Red Hat Security Advisory: cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:21390</link>
      <description>&lt;p&gt;cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:21390</guid>
    </item>
    <item>
      <title>RLSA-2026:21468 — Important: cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:21468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI (CVE-2026-4802)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI (CVE-2026-4802)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:21468</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2005-1 — Security update for cockpit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2005-1</link>
      <description>&lt;p&gt;Security update for cockpit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cockpit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2005-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-4802</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4802</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: cockpit, Ubuntu:20.04:LTS: cockpit, Ubuntu:22.04:LTS: cockpit, Ubuntu:24.04:LTS: cockpit, Ubuntu:25.10: cockpit, Ubuntu:26.04:LTS: cockpit&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: cockpit, Ubuntu:20.04:LTS: cockpit, Ubuntu:22.04:LTS: cockpit, Ubuntu:24.04:LTS: cockpit, Ubuntu:25.10: cockpit, Ubuntu:26.04:LTS: cockpit&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4802</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1699 — Red Hat Enterprise Linux (Cockpit): Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1699</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (Cockpit) ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (Cockpit) ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1699</guid>
    </item>
  </channel>
</rss>
