Junglewise Threat Intelligence

CVE-2026-4631: Red Hat Cockpit OS command injection in remote login feature

CVE-2026-4631 · Severity: critical · CVSS 9.8 · Published 2026-04-07

Vendors: Red Hat.

Executive brief

Cockpit is a web-based interface used to manage and administer Linux servers. A critical vulnerability allows an unauthenticated attacker to take complete control of the server by sending a specially crafted login request. This exploit bypasses normal security checks, potentially leading to full system compromise, data theft, or service disruption without requiring any valid usernames or passwords.

Technical details

A command injection vulnerability (CWE-78) exists in Cockpit's web service (cockpit-ws) component. The remote login feature fails to validate or sanitize user-supplied hostnames and usernames before passing them as arguments to the underlying SSH client. An unauthenticated attacker can craft a malicious HTTP request to the login endpoint to inject SSH options or shell commands. Because this occurs during the initial authentication flow before credentials are verified, it allows for remote code execution with the privileges of the Cockpit process. Red Hat has released security updates (RHSA-2026:7381, RHSA-2026:7382) to address this by enforcing stricter handling of command-line arguments.

Affected products

  • Red Hat Cockpit RHEL 9, RHEL 10, RHEL 9.6 EUS, RHEL 10.0 EUS

Timeline

  • 2026-04-07: disclosed
  • 2026-04-10: patched: Red Hat released security advisories and updated packages.

References