Vulnary
← back to the feed
Critical· 9.8

CVE-2026-4631

Cockpit’s remote login feature lets an attacker send a crafted HTTP request that injects malicious SSH options or shell commands, enabling code execution on the host before any authentication occurs. No valid credentials are needed, so the flaw can be exploited by anyone with network access to the Cockpit web service. The result is a full compromise of the affected system.

publishedApr 7, 2026
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
14%
96th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 18, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Any installation of Cockpit that exposes the remote login feature and has not applied a patch. Typical users are system administrators managing Linux servers via Cockpit.

02

Real-world impact

An attacker can run arbitrary commands on the host, effectively taking complete control of the server, including reading, modifying, or deleting data and installing malware.

03

Why this severity

The CVSS score of 9.8 reflects that the vulnerability is network‑accessible, requires no privileges, and grants full compromise of confidentiality, integrity, and availability. The attack can be performed without any user interaction or authentication.

04

What to do about it

no official fix yet
interim mitigations
  • Restrict access to the Cockpit web service to trusted networks or IP ranges.
  • Disable the remote login feature if it is not required for your environment.
  • Monitor for vendor updates or patches that address this issue.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources.

05

Timeline

  1. Apr 7, 2026 · Apr 7, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 18h ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →