CVE-2026-38992
CRITICALCockpit < 2.14.0 - Remote Code Execution via Filter Parameter MongoLite $func Operator
Title source: llmDescription
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
References (2)
Core 2
Scores
CVSS v3
9.8
EPSS
0.0043
EPSS Percentile
33.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
cockpit-hq/cockpit
0 - 2.14.0Packagist
Published
Apr 29, 2026
Tracked Since
Apr 29, 2026