PT-2026-57916 · Cockpit Hq+1 · Cockpit Cms+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cockpit CMS (affected versions not specified)
Description
A path traversal issue exists in the Bucket file storage API endpoint '/system/buckets/api'. The
api() function in modules/System/Controller/Buckets.php uses a sanitization method that allows '..' and '../' sequences in the bucket variable. This allows the Flysystem WhitespacePathNormalizer to resolve the path to the uploads storage root. Consequently, an authenticated user with low privileges can list, upload, and delete files across all buckets, including those belonging to other users or roles.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cockpit Cms
Cockpit