agentejo Vulnerabilities and Affected Products
Vulnerabilities associated with cockpit.
Products
Clear product- cockpit3 vulnerabilities
- Cockpit CMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-38992CRITICAL | Cockpit is vulnerable to arbitrary code executionCockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. CWE-94Apr 29, 2026 | CVSS9.8v3.1 | EPSS0.426% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4825CRITICAL | Unrestricted Upload of File with Dangerous Type vulnerability on Cockpit CMS from AgentejoA vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure. CWE-434May 13, 2024 | CVSS9.8v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-35131CRITICAL | agentejo cockpit Improper Control of Generation of Code ('Code Injection')Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI. | CVSS9.8v3.1 | EPSS51.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |