Account Enumeration Vulnerability in Cockpit CMS by Cockpit HQ
CVE-2026-82449

6.9MEDIUM

Key Information:

Vendor

Cockpit-hq

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82449?

Cockpit CMS prior to version 2.14.1 is susceptible to an account enumeration issue due to inconsistencies in the authentication check process. Attackers can exploit variations in response times during the password verification stage to ascertain the existence of user accounts. When valid accounts are queried, the bcrypt verification process initiates, resulting in a delayed response; conversely, non-existent accounts yield immediate outcomes. This vulnerability emphasizes the importance of uniform response times for login requests to mitigate potential exploitation by malicious actors.

Affected Version(s)

cockpit 0 < 2.14.1

cockpit 2.14.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matéo Florian Callec
.