Account Enumeration Vulnerability in Cockpit CMS by Cockpit HQ
CVE-2026-82449
6.9MEDIUM
What is CVE-2026-82449?
Cockpit CMS prior to version 2.14.1 is susceptible to an account enumeration issue due to inconsistencies in the authentication check process. Attackers can exploit variations in response times during the password verification stage to ascertain the existence of user accounts. When valid accounts are queried, the bcrypt verification process initiates, resulting in a delayed response; conversely, non-existent accounts yield immediate outcomes. This vulnerability emphasizes the importance of uniform response times for login requests to mitigate potential exploitation by malicious actors.
Affected Version(s)
cockpit 0 < 2.14.1
cockpit 2.14.1
