Junglewise Threat Intelligence

CVE-2026-72557: Cockpit CMS unrestricted file upload vulnerability

CVE-2026-72557 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Cockpit-HQ Cockpit.

Executive brief

Cockpit CMS is a content management platform used to manage website assets and content. A vulnerability in version 2.6.0 allows any authenticated user to upload files of any type, including executable PHP scripts, to a web-accessible location. An attacker with valid login credentials can exploit this to upload a malicious script and execute arbitrary commands on the server, potentially leading to complete system compromise.

Technical details

This is an unrestricted file upload vulnerability in the asset upload endpoint of Cockpit CMS 2.6.0. The root cause is that the allowed_uploads configuration defaults to a wildcard (*) with no validation of file extensions or MIME types, and uploaded files are stored in a publicly accessible directory. An authenticated attacker can upload a PHP webshell via the asset upload mechanism and then access it through the web server to execute arbitrary OS commands. Authentication is required to exploit this vulnerability; however, this includes any authenticated user account, not just administrative accounts. Patches or version updates to restrict file uploads should be applied.

Affected products

  • Cockpit-HQ Cockpit 2.6.0

Timeline

  • 2026-08-11: disclosed

References