logo

CVE-2026-4631: Critical 9.8 RCE Flaw in Cockpit Allows Unauthenticated Server Takeover

ID: 39e8d531-3cca-5440-8f94-6b1a4192ae32

STIX ID: report--39e8d531-3cca-5440-8f94-6b1a4192ae32

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2026-4631, CVSS 9.8) in Cockpit's remote login feature allows attackers to inject SSH options or shell commands during the web login flow, potentially yielding full host takeover; administrators are advised to upgrade to Cockpit 360 or apply the referenced patches/backports, with a short-term mitigation of disabling the "Login To" option.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.