CVE-2018-1000226

CRITICAL NUCLEI

Cobbler <2.6.11 - Privilege Escalation

Title source: llm

Description

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

Nuclei Templates (1)

Cobbler - Authentication Bypass
CRITICALby c-sh0
Shodan: http.title:"cobbler web interface"
FOFA: title="cobbler web interface"

Scores

CVSS v3 9.8
EPSS 0.6001
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
cobblerd/cobbler 2.0.0
pypi/cobbler 0 - 3.0.0PyPI
Published Aug 20, 2018
Tracked Since Feb 18, 2026