Executive brief
Cockpit CMS is a popular content management platform used to manage website content and user accounts. A timing-based vulnerability in the authentication system allows attackers to discover which user accounts exist by measuring response times—accounts that exist take longer to respond because the system verifies passwords using bcrypt, while non-existent accounts respond immediately. This information leakage can enable targeted attacks on known accounts.
Technical details
The auth check endpoint in Cockpit CMS before version 2.14.1 is vulnerable to account enumeration via timing side-channel analysis. The root cause is inconsistent response times during password verification: legitimate accounts trigger computationally expensive bcrypt password verification, while non-existent accounts return immediately without verification, creating a measurable timing discrepancy. An attacker can send multiple authentication requests with different usernames and measure response latency to determine which accounts exist, requiring no authentication and only network reachability to the auth endpoint. By correlating timing patterns across requests, attackers can build a list of valid usernames for subsequent brute-force or credential-stuffing attacks. The vulnerability was patched in version 2.14.1.
Affected products
- Cockpit-HQ Cockpit CMS before 2.14.1
Timeline
- 2026-08-29: disclosed
- 2026: patched: Fixed in version 2.14.1