UBUNTU-CVE-2026-92747

Source
https://ubuntu.com/security/CVE-2026-92747
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-92747.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-92747
Upstream
  • CVE-2026-92747
Published
2026-09-21T00:00:00Z
Modified
2026-09-21T21:40:55Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as rootPassword and userPassword. This occurs when the install_machine.py script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.

References

Affected packages

Ubuntu:22.04:LTS / cockpit-machines

Package

Name
cockpit-machines
Purl
pkg:deb/ubuntu/cockpit-machines?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
251-1
254-1
255-1
256-1
258-1
259-1
260-1
261-1
262-1
263-1
264-1
265-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "cockpit-machines",
            "binary_version":  "265-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-92747.json"

Ubuntu:24.04:LTS / cockpit-machines

Package

Name
cockpit-machines
Purl
pkg:deb/ubuntu/cockpit-machines?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
299-1
300-1
301-1
302-1
303-1
304-1
305-1
306-1
307-1
310-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "cockpit-machines",
            "binary_version":  "310-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-92747.json"

Ubuntu:26.04:LTS / cockpit-machines

Package

Name
cockpit-machines
Purl
pkg:deb/ubuntu/cockpit-machines?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
339-1
341-1
343-1
345-1
346-1
347-1
348-1
351-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "cockpit-machines",
            "binary_version":  "351-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-92747.json"