File Access Vulnerability in agentejo Cockpit CMS by Agentejo
CVE-2026-13533
Key Information:
- Vendor
Agentejo
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13533?
A security vulnerability in Agentejo's Cockpit CMS allows remote attackers to access sensitive files or directories due to improper handling in the Spyc::YAMLLoad function located in the /config/config.yaml file. This flaw poses significant security risks, as it can lead to unauthorized disclosure of configuration settings, making it crucial for users to review and amend their configuration to mitigate potential exploits. Despite prior notification to the vendor regarding this issue, no response or action has been taken.
Affected Version(s)
Cockpit CMS 0.12.0
Cockpit CMS 0.12.1
Cockpit CMS 0.12.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
