CVE-2026-38992

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
Configurations

No configuration.

History

30 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 15:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-38992

Mitre link : CVE-2026-38992

CVE.ORG link : CVE-2026-38992


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')