Exposed Sensitive Credentials in Cockpit's Virtual Machine Management Tool
CVE-2026-92747

5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 September 2026

What is CVE-2026-92747?

A vulnerability exists in the cockpit-machines tool that can allow local attackers to inspect running processes and access sensitive guest virtual machine credentials, including rootPassword and userPassword. This exposure occurs during the installation process when the install_machine.py script unintentionally passes these credentials as JSON command-line arguments. The risk is amplified during the active installation workflow and is contingent upon the host process visibility settings. Proper mitigation strategies should be implemented to safeguard against unauthorized access.

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.