CVE-2026-4631 Details
Description
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
A vulnerability in Cockpit's remote login feature allows for unauthenticated remote code execution. This issue arises because user-supplied hostnames and usernames are sent to the SSH client without proper validation or sanitization. An attacker with network access to the Cockpit web service can inject malicious SSH options or commands, executing code on the Cockpit host without needing valid credentials. The vulnerability exists in Cockpit versions 327 and later, when used with OpenSSH versions prior to 9.6, and requires remote host login to be enabled, which is the default setting.
Users can update to Cockpit version 327 or later and ensure OpenSSH is version 9.6 or later. For systems with OpenSSH 9.6 or later, no action is needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | redhat-SADP |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 27, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | CVE Modified | [email protected] |
| Apr 10, 2026 | CVE Modified | CVE |
| Apr 10, 2026 | CVE Modified | [email protected] |
| Apr 10, 2026 | CVE Modified | [email protected] |
| Apr 7, 2026 | New CVE Received | [email protected] |