CVE-2026-4631 allows remote attackers to execute arbitrary code on a Cockpit host by injecting malicious SSH options via a crafted HTTP request to the login endpoint due to insufficient input validation of user-supplied hostnames and usernames.
PoC
Cockpit
rce
command-injection
CVE-2026-4631
linux
2r
1t
1c
2i
updated