CVE-2026-105217
published 2026-10-04CVE-2026-105217: Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the…
PriorityP413low3.1CVSS 3.1
AVAACHPRNUINSUCLINAN
EPSS
0.10%
0.9th percentile
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| agentejo | cockpit | — | — |
| cockpit-hq | cockpit | >= 2.12.0 < 2.14.1 | 2.14.1 |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.02.3LOWCVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cockpit-HQ Cockpit up to 2.14.0 information disclosure
vuldb·2026-10-04·CVSS 3.1
CVE-2026-105217 [LOW] Cockpit-HQ Cockpit up to 2.14.0 information disclosure
A vulnerability labeled as problematic has been found in Cockpit-HQ Cockpit up to 2.14.0. Affected by this issue is some unknown functionality. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2026-105217. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
GHSA
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token.
ghsa_unreviewed·2026-10-04
CVE-2026-105217 [LOW] CWE-295 Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token.
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
Red Hat
cockpit: Cockpit CMS: Sensitive token disclosure via disabled TLS certificate verification
vendor_redhat·2026-10-04·CVSS 3.1
CVE-2026-105217 [LOW] CWE-295 cockpit: Cockpit CMS: Sensitive token disclosure via disabled TLS certificate verification
cockpit: Cockpit CMS: Sensitive token disclosure via disabled TLS certificate verification
A flaw was found in Cockpit CMS. The application disables Transport Layer Security (TLS) certificate verification when making background requests to restart web workers. An attacker in a position to intercept network traffic could exploit this flaw by presenting an arbitrary certificate, allowing them to capture sensitive worker authentication tokens and trigger background worker tasks.
Package: cockpit (Red Hat Enterprise Linux 10) - Fix deferred
Package: cockpit (Red Hat Enterprise Linux 7) - Fix deferred
Package: cockpit (Red Hat Enterprise Linux 8) - Fix deferred
Package: cockpit (Red Hat Enterprise Linux 9) - Fix deferred
No detection rules found.
No public exploits indexed.
https://github.com/Cockpit-HQ/Cockpithttps://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/cron.php#L70-L102https://github.com/Cockpit-HQ/Cockpit/commit/c611492adc17362578faa97f9c30b41e6c16e040https://github.com/Cockpit-HQ/Cockpit/issues/318https://www.vulncheck.com/advisories/cockpit-cms-2.12.0-before-2.14.1-disabled-tls-verification-via-cron-php
2026-10-04
Published