CVE-2026-72557

Source
https://cve.org/CVERecord?id=CVE-2026-72557
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72557.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72557
Published
2026-08-11T11:11:53Z
Modified
2026-09-05T03:31:08Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Cockpit CMS Cockpit CMS - Unrestricted File Upload
Details

An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server.

Database specific
{
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72557.json"
}
References

Affected packages

Git / github.com/cockpit-hq/cockpit

Affected ranges

Type
GIT
Repo
https://github.com/cockpit-hq/cockpit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72557.json"