PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Web Vulnerabilities·Updated Sep 26, 2026

CVE-2026-58467 Scanner

CVE-2026-58467 Scanner - Path Traversal/Local File Inclusion (LFI) vulnerability in Cockpit CMS

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
1
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
8.2
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cockpitby cockpit-hq
0
Updated Sep 26, 2026View on NVD →
Detail

Cockpit CMS is a headless content management system primarily used by web developers to manage and deliver content through APIs. It is designed to be flexible and extensible, making it suitable for a wide range of web applications. Often used in environments that necessitate a lightweight and easy-to-integrate content management solution, it is employed by startups and SMEs for fast and dynamic web service deployment. With features such as custom collections, file management, and API access, it serves various sectors including media, education, and technology. Cockpit CMS is utilized in scenarios where collaboration between content creators and developers is essential, providing an efficient content lifecycle management system.

The Path Traversal and Local File Inclusion (LFI) vulnerability found in Cockpit CMS allows attackers to manipulate file paths to access files outside the web root directory. This vulnerability typically arises when the software inadequately validates user input, allowing traversal using sequences such as "../../". If exploited, it grants unauthorized access to sensitive system files, potentially leading to information leakage or system compromise. The vulnerability impacts systems that use PHP's built-in CLI server or non-normalizing reverse proxies, particularly affecting routes starting with certain path segments. It highlights significant risks in environments where stringent validation of file access paths is not enforced.

Technical details of this vulnerability reveal that it stems from insufficient sanitation of path sequences in the HTTP request's PATH_INFO. An attacker can craft a request with malicious path sequences to access arbitrary files on the server, such as "/etc/passwd", if running under the specified vulnerable conditions. The core issue lies in the handling of these paths without adequate normalization checks. It is crucial for the affected systems to address these path manipulation risks to prevent directory traversal attacks that can disclose confidential server information. The vulnerability is particularly exploitable by remote, unauthenticated users, increasing the risk exposure significantly.

If the Path Traversal and Local File Inclusion vulnerability is exploited, it can lead to the exposure of sensitive information such as user credentials and system configuration files. This, in turn, can result in unauthorized access and potential further exploitation of the system. Malicious actors might leverage this access to elevate privileges or execute other attacks, such as installing backdoors or initiating denial of service. The vulnerability potentially undermines user privacy and system integrity by making confidential information accessible to unauthorized users, thereby posing a substantial security threat.

REFERENCES

Solution Advice
  • Upgrade your Cockpit CMS installation to version 2.14.1 or higher.
  • Implement strict input validation to prevent directory traversal in paths.
  • Ensure your web server settings restrict filesystem access to only necessary directories.
  • Consider using a web application firewall (WAF) to detect and block potential intrusion attempts.
  • Regularly audit server settings and update configurations to align with security best practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.