CVE-2026-82449
published 2026-08-29CVE-2026-82449: Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.24%
15.9th percentile
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which accounts exist by observing that existing accounts trigger bcrypt verification while non-existent accounts return immediately.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cockpit-hq | cockpit | < 2.14.1 | 2.14.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cockpit-HQ Cockpit up to 2.14.0 Auth Check Endpoint information disclosure
vuldb·2026-08-29·CVSS 5.3
CVE-2026-82449 [MEDIUM] Cockpit-HQ Cockpit up to 2.14.0 Auth Check Endpoint information disclosure
A vulnerability was found in Cockpit-HQ Cockpit up to 2.14.0. It has been classified as problematic. Impacted is an unknown function of the component Auth Check Endpoint. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-82449. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification.
ghsa_unreviewed·2026-08-29
CVE-2026-82449 [MEDIUM] CWE-208 Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification.
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which accounts exist by observing that existing accounts trigger bcrypt verification while non-existent accounts return immediately.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Cockpit-HQ/Cockpithttps://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/modules/App/Controller/Auth.phphttps://github.com/Cockpit-HQ/Cockpit/commit/5d65ae7b63a261a63e8809e5fba857ef3eadb2achttps://link.mateocallec.com/MFC-2026-001https://www.vulncheck.com/advisories/cockpit-cms-before-2.14.1-account-enumeration-via-auth-timing
2026-08-29
Published