DEBIAN-CVE-2026-92747

Source
https://security-tracker.debian.org/tracker/CVE-2026-92747
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92747.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-92747
Upstream
  • CVE-2026-92747
Published
2026-09-18T18:18:16Z
Modified
2026-09-19T05:00:19Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as rootPassword and userPassword. This occurs when the install_machine.py script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.

References

Affected packages

Debian:12 / cockpit-machines

Package

Name
cockpit-machines
Purl
pkg:deb/debian/cockpit-machines?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
288-1
292-1
293-1
294-1
295-1~bpo12+1
295-1
296-1
297-1~bpo12+1
297-1
298-1~bpo12+1
298-1
299-1~bpo12+1
299-1
300-1~bpo12+1
300-1
301-1
302-1~bpo12+1
302-1
303-1~bpo12+1
303-1
304-1~bpo12+1
304-1
305-1~bpo12+1
305-1
306-1
307-1~bpo12+1
307-1
309-1~bpo12+1
309-1
310-1~bpo12+1
310-1
312-1
313-1
313-2
313-3
314-1
314-2~bpo12+1
314-2
315-1~bpo12+1
315-1
316-1
317-1~bpo12+1
317-1
318-1~bpo12+1
318-1
319-1~bpo12+1
319-1
320-1~bpo12+1
320-1
321-1
322-1
323-1~bpo12+1
323-1
324-1~bpo12+1
324-1
325-1
325-2
326-1
327-1~bpo12+1
327-1
328-1
329-1~bpo12+1
329-1
330-1
331-1
332-1~bpo12+1
332-1
334-1
335-1
336-1
338-1~bpo13+1
338-1
339-1~bpo13+1
339-1
341-1~bpo13+1
341-1
343-1~bpo13+1
343-1
345-1~bpo13+1
345-1
346-1~bpo13+1
346-1
347-1~bpo13+1
347-1
348-1~bpo13+1
348-1
350-1~bpo13+1
350-1
351-1~bpo13+1
351-1
353-1
353-2
353-3~bpo13+1
353-3
355-1~bpo13+1
355-1
356-1~bpo13+1
356-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92747.json"

Debian:13 / cockpit-machines

Package

Name
cockpit-machines
Purl
pkg:deb/debian/cockpit-machines?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
332-1
334-1
335-1
336-1
338-1~bpo13+1
338-1
339-1~bpo13+1
339-1
341-1~bpo13+1
341-1
343-1~bpo13+1
343-1
345-1~bpo13+1
345-1
346-1~bpo13+1
346-1
347-1~bpo13+1
347-1
348-1~bpo13+1
348-1
350-1~bpo13+1
350-1
351-1~bpo13+1
351-1
353-1
353-2
353-3~bpo13+1
353-3
355-1~bpo13+1
355-1
356-1~bpo13+1
356-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92747.json"

Debian:14 / cockpit-machines

Package

Name
cockpit-machines
Purl
pkg:deb/debian/cockpit-machines?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
332-1
334-1
335-1
336-1
338-1~bpo13+1
338-1
339-1~bpo13+1
339-1
341-1~bpo13+1
341-1
343-1~bpo13+1
343-1
345-1~bpo13+1
345-1
346-1~bpo13+1
346-1
347-1~bpo13+1
347-1
348-1~bpo13+1
348-1
350-1~bpo13+1
350-1
351-1~bpo13+1
351-1
353-1
353-2
353-3~bpo13+1
353-3
355-1~bpo13+1
355-1
356-1~bpo13+1
356-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92747.json"