Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agentejo
Agentejo cockpit |
|
| CPEs | cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Agentejo
Agentejo cockpit |
Tue, 14 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Jul 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only. | |
| Title | Cockpit CMS Missing Authorization in Bucket File Storage API | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-13T22:33:39.717Z
Updated: 2026-07-14T21:34:35.253Z
Reserved: 2026-06-25T18:48:00.282Z
Link: CVE-2026-57855
Updated: 2026-07-14T12:43:36.978Z
No data.
No data.