CVE-2026-4631: Critical 9.8 RCE Flaw in Cockpit Allows Unauthenticated Server Takeover
ID: 39e8d531-3cca-5440-8f94-6b1a4192ae32
STIX ID: report--39e8d531-3cca-5440-8f94-6b1a4192ae32
Feed Name: securityonline.info
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2026-4631, CVSS 9.8) in Cockpit's remote login feature allows attackers to inject SSH options or shell commands during the web login flow, potentially yielding full host takeover; administrators are advised to upgrade to Cockpit 360 or apply the referenced patches/backports, with a short-term mitigation of disabling the "Login To" option.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
