Vendor
high
advisory
Command Injection in Cockpit CMS FFmpeg Integration
1 rule 1 TTP 1 CVECockpit CMS versions 2.14.0 and prior are vulnerable to authenticated command injection via malicious filenames processed by the FFmpeg integration.
Cockpit CMS
web-application-vulnerability
remote-code-execution
injection
cockpit-cms
1r
1t
1c
high
advisory
CVE-2026-57856 - Cockpit CMS Path Traversal Vulnerability
1 rule 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-57856) exists in the Bucket file storage API of Cockpit CMS, allowing authenticated low-privileged users to exploit a flaw in bucket name sanitization to access, upload, or delete files across all buckets by using crafted '..' sequences.
Cockpit CMS
path-traversal
privilege-escalation
data-exfiltration
api-abuse
1r
1t
1c