Junglewise Threat Intelligence

CVE-2026-57855: Cockpit CMS missing authorization and path traversal in Buckets API

CVE-2026-57855 · Severity: high · CVSS 8.8 · Published 2026-07-13

Technologies: Cockpit-HQ Cockpit CMS.

Executive brief

Cockpit CMS, a platform used for managing website content and file storage, contains a security flaw in its file management system. This vulnerability allows any logged-in user, even those with limited permissions, to view, upload, rename, or delete files in any storage area, including those reserved for administrators. This could lead to the theft of sensitive data, unauthorized modification of website content, or the deletion of critical system files.

Technical details

A missing authorization vulnerability exists in the Cockpit CMS Bucket file storage API. The api() method in modules/System/Controller/Buckets.php fails to perform Access Control List (ACL) or role-based checks before executing commands such as ls, upload, removefiles, rename, and createfolder. Additionally, the bucket name parameter is susceptible to path traversal (CWE-22) using '../' sequences, allowing access to the filesystem root. An authenticated attacker with low-level privileges (e.g., editor) can exploit this to gain full control over the file storage layer. The issue is resolved in version 2.14.0.

Affected products

  • Cockpit-HQ Cockpit CMS < 2.14.0

Timeline

  • 2026-03-30: patched: Version 2.14.0 released
  • 2026-06-04: disclosed: Reported to VulnCheck for coordinated disclosure
  • 2026-07-13: advisory: NVD and VulnCheck advisory published

References