/Vulnerability Library

Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion

CVE-2026-58467
Early Release

Description

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion (LFI) vulnerability when executed under PHP's built-in CLI server (PHP_SAPI == 'cli-server') or non-normalizing reverse proxies. The application fails to sanitize dot-dot sequences in PATH_INFO routes starting with '/:' and containing '/storage/'. Unauthenticated remote attackers can traverse outside the designated directory to read arbitrary system files.

Severity

High

CVSS Score

8.2

Exploit Probability

2%

Affected Product

cockpit

Published Date

September 21, 2026

Template Author

abdullah shahid (comradezephyr)

CVE-2026-58467.yaml
8.2Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-58467
CWE ID:
cwe-22

References

https://www.cve.org/CVERecord?id=CVE-2026-58467https://nvd.nist.gov/vuln/detail/CVE-2026-58467https://github.com/cockpit-hq/cockpit/compare/2.14.0...2.14.1https://github.com/geo-chen/oss/blob/main/cockpit.md

Remediation Steps

Upgrade to Cockpit CMS version 2.14.1 or higher.