TLS Certificate Verification Issue in Cockpit CMS by Cockpit HQ
CVE-2026-105217
2.3LOW
What is CVE-2026-105217?
A serious issue has been identified in Cockpit CMS versions prior to 2.14.1, where the TLS certificate verification is disabled during the restart request of the cron.php web worker. This flaw poses a significant risk, as it enables network attackers to carry out man-in-the-middle attacks by exploiting the lack of verification, allowing them to capture sensitive worker tokens. Attackers can present fraudulent certificates in the outbound path to the site's URL, potentially gaining unauthorized access to the web worker's crucial data.
Affected Version(s)
cockpit 2.12.0 < 2.14.1
