CVE Feed

    Dashboard / CVE / CVE-2026-34965

    CVE-2026-34965

    Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP code through rule parameters which is written directly to server-side PHP files and executed via include() to achieve arbitrary command execution on the underlying server.

    Published:Apr 29, 2026
    Last Modified:Jul 14, 2026
    EPS:Apr 29, 2026
    EPSS Score:0.00825
    CVSS Score:8.8

    Affected Products

    Vendor
    Agentejo
    Product
    Cockpit
    Vendor
    Cockpit-hq
    Product
    Cockpit

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High