Authenticated Remote Code Execution Vulnerability in Cockpit CMS
CVE-2026-34965
Key Information:
- Vendor
Cockpit
- Status
- Vendor
- CVE Published:
- 29 April 2026
Badges
What is CVE-2026-34965?
Cockpit CMS contains an authenticated remote code execution vulnerability that affects the /cockpit/collections/save_collection endpoint. This flaw enables attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. By exploiting this vulnerability, attackers can execute malicious PHP code as it is directly written to server-side PHP files and executed through the include() function, leading to full compromise of the underlying server.
Affected Version(s)
Cockpit CMS 0 <= 494765e
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
