CVE-2026-38992 Details
Description
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
A vulnerability allowing arbitrary code execution has been identified in Cockpit CMS versions through 2.13.5. The issue arises from the filter parameter in multiple endpoints, which can be exploited to execute system commands on the server via the MongoLite $func operator. This vulnerability was reported to the Cockpit CMS team, who promptly developed and released a patch in version 2.14.0.
Users are advised to update to Cockpit CMS version 2.14.0, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 29, 2026CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/ | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/ | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0 | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Cockpit CMS | <= 2.13.5 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | New CVE Received | [email protected] |
Volerion