TLS Certificate Verification Issue in Cockpit CMS by Cockpit HQ
CVE-2026-105217

2.3LOW

Key Information:

Vendor

Cockpit-hq

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105217?

A serious issue has been identified in Cockpit CMS versions prior to 2.14.1, where the TLS certificate verification is disabled during the restart request of the cron.php web worker. This flaw poses a significant risk, as it enables network attackers to carry out man-in-the-middle attacks by exploiting the lack of verification, allowing them to capture sensitive worker tokens. Attackers can present fraudulent certificates in the outbound path to the site's URL, potentially gaining unauthorized access to the web worker's crucial data.

Affected Version(s)

cockpit 2.12.0 < 2.14.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.