Junglewise Threat Intelligence

CVE-2026-82449: Cockpit CMS account enumeration in auth check endpoint

CVE-2026-82449 · Severity: medium · CVSS 5.3 · Published 2026-08-29

Technologies: Cockpit-HQ Cockpit CMS.

Executive brief

Cockpit CMS is a popular content management platform used to manage website content and user accounts. A timing-based vulnerability in the authentication system allows attackers to discover which user accounts exist by measuring response times—accounts that exist take longer to respond because the system verifies passwords using bcrypt, while non-existent accounts respond immediately. This information leakage can enable targeted attacks on known accounts.

Technical details

The auth check endpoint in Cockpit CMS before version 2.14.1 is vulnerable to account enumeration via timing side-channel analysis. The root cause is inconsistent response times during password verification: legitimate accounts trigger computationally expensive bcrypt password verification, while non-existent accounts return immediately without verification, creating a measurable timing discrepancy. An attacker can send multiple authentication requests with different usernames and measure response latency to determine which accounts exist, requiring no authentication and only network reachability to the auth endpoint. By correlating timing patterns across requests, attackers can build a list of valid usernames for subsequent brute-force or credential-stuffing attacks. The vulnerability was patched in version 2.14.1.

Affected products

  • Cockpit-HQ Cockpit CMS before 2.14.1

Timeline

  • 2026-08-29: disclosed
  • 2026: patched: Fixed in version 2.14.1

References