Executive brief
Cockpit is vulnerable to arbitrary code execution
Affected products
- Packagist cockpit-hq/cockpit
Junglewise Threat Intelligence
CVE-2026-38992 · Severity: low · CVSS 3.1 · Published 2026-04-29
Technologies: cockpit-hq/cockpit (Packagist). Vendors: Packagist.
Cockpit is vulnerable to arbitrary code execution