<Vulnerability name="CVE-2026-4802">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-05-11T12:34:26</PublicDate>
    <Bugzilla id="2451155" url="https://bugzilla.redhat.com/show_bug.cgi?id=2451155" xml:lang="en:us">
cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.0</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-78</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
    </Details>
    <Statement xml:lang="en:us">
An Important arbitrary command execution flaw exists in Cockpit's system logs UI. This vulnerability allows a remote attacker to execute arbitrary commands on the host by exploiting unsanitized user-controlled parameters within crafted links. This impacts Red Hat Enterprise Linux systems where Cockpit is installed and accessible.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank Gabriel Rodrigues (HAKAI) for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Operational risk reduction until fixes are available: restrict access to Cockpit to trusted networks/users only, and avoid opening untrusted crafted Cockpit URLs
    </Mitigation>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-05-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21676">RHSA-2026:21676</Advisory>
        <Package name="cockpit">cockpit-0:356.2-1.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21390">RHSA-2026:21390</Advisory>
        <Package name="cockpit">cockpit-0:334.2-1.el10_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-05-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21700">RHSA-2026:21700</Advisory>
        <Package name="cockpit">cockpit-0:310.8-1.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_aus:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21516">RHSA-2026:21516</Advisory>
        <Package name="cockpit">cockpit-0:264.3-1.el8_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_tus:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21516">RHSA-2026:21516</Advisory>
        <Package name="cockpit">cockpit-0:264.3-1.el8_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_e4s:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21516">RHSA-2026:21516</Advisory>
        <Package name="cockpit">cockpit-0:264.3-1.el8_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_tus:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21515">RHSA-2026:21515</Advisory>
        <Package name="cockpit">cockpit-0:286.2-1.el8_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_e4s:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21515">RHSA-2026:21515</Advisory>
        <Package name="cockpit">cockpit-0:286.2-1.el8_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21468">RHSA-2026:21468</Advisory>
        <Package name="cockpit">cockpit-0:356.2-1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21468">RHSA-2026:21468</Advisory>
        <Package name="cockpit">cockpit-0:356.2-1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.0">
        <ProductName>Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21395">RHSA-2026:21395</Advisory>
        <Package name="cockpit">cockpit-0:264.3-1.el9_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21394">RHSA-2026:21394</Advisory>
        <Package name="cockpit">cockpit-0:286.3-1.el9_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21647">RHSA-2026:21647</Advisory>
        <Package name="cockpit">cockpit-0:311.3-1.el9_4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21392">RHSA-2026:21392</Advisory>
        <Package name="cockpit">cockpit-0:334.3-1.el9_6</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>cockpit</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-4802
https://nvd.nist.gov/vuln/detail/CVE-2026-4802
https://github.com/cockpit-project/cockpit/blob/e204cd130/pkg/systemd/logsJournal.jsx#L206-L210
    </References>
    <CSAw>True</CSAw>
</Vulnerability>