Stored Cross-Site Scripting Vulnerability in Cockpit CMS
CVE-2026-23695

5.1MEDIUM

Key Information:

Vendor

Cockpit-hq

Status
Vendor
CVE Published:
15 May 2026

What is CVE-2026-23695?

Cockpit CMS versions prior to 2.14.0 are vulnerable to a stored cross-site scripting attack due to improper sanitization of template strings in the Set field type's Display template option. This vulnerability allows attackers with specific permissions to inject arbitrary JavaScript code into the Display template. When users view the collection items list, this malicious script executes in their browsers, potentially compromising sensitive information and user sessions.

Affected Version(s)

Cockpit 0 <= 2.14.0

Cockpit 0 <= 2.14.0

Cockpit 72a83fcfe85ad8330e9ae834bc02fa517b5749e9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D6fault
VulnCheck
.