lowCVSS 6.3Vulnerability

CVE-2026-6626

A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

summary
Cockpit has NoSQL Injection Through Content Aggregation Pipelines
severity
low
epss_score
0.00233
cvss_score
6.3
ghsa_published
2026-04-20T12:32:01Z
source_url
https://github.com/advisories/GHSA-5pv2-86qj-5jf9
ghsa_updated
2026-04-23T21:47:56Z
ghsa_id
GHSA-5pv2-86qj-5jf9
cve_id
CVE-2026-6626
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.1405

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS (1)

[Software]composer/cockpit-hq/cockpit

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/cockpit-hq/cockpit

Explore deeper with Ninja Signal's threat intelligence graph