Product
high
advisory
CVE-2026-57856 - Cockpit CMS Path Traversal Vulnerability
1 rule 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-57856) exists in the Bucket file storage API of Cockpit CMS, allowing authenticated low-privileged users to exploit a flaw in bucket name sanitization to access, upload, or delete files across all buckets by using crafted '..' sequences.
Cockpit CMS
path-traversal
privilege-escalation
data-exfiltration
api-abuse
1r
1t
1c
critical
advisory
Cockpit CMS Authenticated Remote Code Execution via Code Injection
2 rules 1 TTP 1 CVECockpit CMS is vulnerable to authenticated remote code execution via PHP code injection in the /cockpit/collections/save_collection endpoint, enabling attackers with collection management privileges to execute arbitrary commands on the server.
Cockpit CMS
rce
code-injection
cockpit-cms
2r
1t
1c