Fortify
← All intel
NVD/NISTCVE-2026-4802

Cockpit Flaw Enables Remote Command Execution

PublishedMay 11, 2026 at 2:16 PM·high

What happened

A high-severity vulnerability (CVE-2026-4802) in Cockpit, the popular Linux server management web interface, lets remote attackers run arbitrary shell commands by injecting metacharacters into crafted links shown in the system logs UI. Successful exploitation could fully compromise the host, putting any organization using Cockpit to administer Linux servers at risk. Admins should apply vendor patches as soon as they are available and restrict access to the Cockpit interface in the meantime.

Tags

#cockpit#linux#command-injection#cve-2026-4802

Source reference

https://access.redhat.com/security/cve/CVE-2026-4802

See how Fortify maps this threat to your compliance posture.

14-day free trial · no credit card · HIPAA, SOC 2, ISO 27001, GDPR

Sign Up →