CVE-2026-4631
Cockpit’s remote login feature lets an attacker send a crafted HTTP request that injects malicious SSH options or shell commands, enabling code execution on the host before any authentication occurs. No valid credentials are needed, so the flaw can be exploited by anyone with network access to the Cockpit web service. The result is a full compromise of the affected system.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Any installation of Cockpit that exposes the remote login feature and has not applied a patch. Typical users are system administrators managing Linux servers via Cockpit.
Real-world impact
An attacker can run arbitrary commands on the host, effectively taking complete control of the server, including reading, modifying, or deleting data and installing malware.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is network‑accessible, requires no privileges, and grants full compromise of confidentiality, integrity, and availability. The attack can be performed without any user interaction or authentication.
What to do about it
- ›Restrict access to the Cockpit web service to trusted networks or IP ranges.
- ›Disable the remote login feature if it is not required for your environment.
- ›Monitor for vendor updates or patches that address this issue.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.
Timeline
- Apr 7, 2026 · Apr 7, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 18h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- access.redhat.com/errata/RHSA-2026:7381
- access.redhat.com/errata/RHSA-2026:7382
- access.redhat.com/errata/RHSA-2026:7383
- access.redhat.com/errata/RHSA-2026:7384
- access.redhat.com/security/cve/CVE-2026-4631
- bugzilla.redhat.com/show_bug.cgi
- github.com/cockpit-project/cockpit/sec…
- openwall.com/lists/oss-security/2026/04/…
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…