Executive brief
Cockpit CMS, a content management system used to manage website data, contains a security flaw in its Buckets component. An authorized user can exploit this to save files in unintended locations on the server or replace existing website assets with malicious versions. This could lead to unauthorized website changes or the hosting of malicious content.
Technical details
A directory traversal vulnerability exists in the Buckets component of Cockpit CMS versions 2.13.5 and earlier. The flaw stems from improper validation of user-supplied paths, allowing an authenticated attacker to bypass restricted directory boundaries. By crafting malicious requests, an attacker can perform arbitrary file writes within the uploads directory or overwrite existing assets with malicious content. This vulnerability is addressed in version 2.14.0, which implements stricter path validation for the Buckets component.
Affected products
- Cockpit-HQ Cockpit CMS <= 2.13.5
Timeline
- 2026-03-25: disclosed: Vulnerability reported to vendor.
- 2026-03-30: patched: Version 2.14.0 released with fix.
- 2026-04-29: advisory: Public disclosure and CVE assignment.