PT-2026-57916 · Cockpit Hq+1 · Cockpit Cms+1

·

CVE-2026-57856

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cockpit CMS (affected versions not specified)
Description A path traversal issue exists in the Bucket file storage API endpoint '/system/buckets/api'. The api() function in modules/System/Controller/Buckets.php uses a sanitization method that allows '..' and '../' sequences in the bucket variable. This allows the Flysystem WhitespacePathNormalizer to resolve the path to the uploads storage root. Consequently, an authenticated user with low privileges can list, upload, and delete files across all buckets, including those belonging to other users or roles.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57856

Affected Products

Cockpit Cms
Cockpit