CVE-2026-57855
HIGHCockpit CMS Missing Authorization in Bucket File Storage API
Title source: cnaDescription
Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only.
References (4)
Core 4
Core References
Patch patch
Patch Commit
https://github.com/Cockpit-HQ/Cockpit/commit/dde2d1d74f5f4e11de42a298918ea8c9684f932c
Technical Description technical-description
https://gist.github.com/sermikr0/821c4edd3c34e98a62a50b07707785bd
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/cockpit-cms-missing-authorization-in-bucket-file-storage-api
Scores
CVSS v3
8.8
EPSS
0.0028
EPSS Percentile
20.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (1)
Cockpit HQ/Cockpit CMS
< 2.14.0
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026