🛡️ OESA-2026-2907 — cockpit
Description
cockpit security update
Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.
Security Fix(es):
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)
Affected software
OESA-2026-2907 is recorded against 1 package.
- cockpit (fixed in 309-8.oe2403sp1)
Timeline and source
Published on 9 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.openeuler.org (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| cockpit | — | 309-8.oe2403sp1 |
References
Similar Threats
- Unknown ALSA-2026:21676
- Unknown ALSA-2026:21700
- Unknown ALSA-2026:21468
- Unknown CLSA-2026-1777452220
- Unknown ALSA-2026:7384
More OESA 2026 advisories
Browse all of OESA 2026 in the advisory index.
Site Security Check
Is cockpit part of your stack?
OESA-2026-2907 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.