Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion
CVE-2026-58467
Early Release
Description
Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion (LFI) vulnerability when executed under PHP's built-in CLI server (PHP_SAPI == 'cli-server') or non-normalizing reverse proxies. The application fails to sanitize dot-dot sequences in PATH_INFO routes starting with '/:' and containing '/storage/'. Unauthenticated remote attackers can traverse outside the designated directory to read arbitrary system files.
Severity
High
CVSS Score
8.2
Exploit Probability
2%
Affected Product
cockpit
Published Date
September 21, 2026
Template Author
abdullah shahid (comradezephyr)
CVE-2026-58467.yaml
8.2Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-58467
CWE ID:
cwe-22
Remediation Steps
Upgrade to Cockpit CMS version 2.14.1 or higher.