VulnerabilityDeferred
CVE-2026-38993
Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component.
MEDIUM 6.5EPSS 0.84%
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Source
- cve@mitre.org
References
- https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/
- https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.14.0
- https://access.redhat.com/security/cve/CVE-2026-38993
- https://bugzilla.redhat.com/show_bug.cgi?id=2463843
- https://felsec.com/posts/cockpit-cms-2.13.5-multi-vulns/
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-38993.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.