Issued at: 2026-05-21
Updated at: 2026-05-21
Synopsis
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Description
Cockpit enables users to administer GNU/Linux servers using a web browser. It
offers network configuration, log inspection, diagnostic reports, SELinux
troubleshooting, interactive command-line sessions, and more.
Security Fix(es):
* cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.