CVE-2026-38992Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-29: 2Mentions · 2026-05-12: 4Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-19: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-04-29: 2Technical Details · 2026-05-12: 3Technical Details · 2026-08-19: 104-2905-1208-19
Signal classification3 categories
Disclosure
571.4%
General
114.3%
PoC
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-05-124
Disclosure3General1
2026-08-191
PoC1
Full discourse7 posts
  • Vulnerability Research Labs@vulnresearchlab
    PoC

    The filter parameter in Cockpit could be used for arbitrary code execution. We built an exploit for the public CVE and verified the vendor patch closes it. 20m 29s and $4.60, end to end. CVE-2026-38992.

    Post summary

    The author built a proof of concept exploit for CVE-2026-38992, demonstrating arbitrary code execution via a filter parameter in Cockpit, and confirmed that the vendor patch mitigates the flaw.

    1000081
    8 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-38992 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text only lists CVE-2026-38992 with CVSS 9.8 and critical severity, offering basic vulnerability metrics but no proof‑of‑concept, exploit, active exploitation or patch information.

    1000034
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-38992 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints.

    Post summary

    The advisory announces that Cockpit v2.13.5 and earlier are vulnerable to arbitrary code execution through a filter parameter, highlighting the severity but providing no exploit code, patch information, or evidence of active exploitation.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-38992 (CVSS 9.8) — multiple products. CVE: CVE-2026-38992 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet announces CVE-2026-38992 as a critical vulnerability with a 9.8 CVSS score, but offers no Proof of Concept, exploit code, or mitigation guidance.

    1000034
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-38992-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only contains a URL and hashtags; no substantive details about CVE‑2026‑38992 are present, making it a general note with no actionable indicators.

    0000029
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-38992 Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run… https://www.cve.org/CVERecord?id=CVE-2026-38992 ----- Traducción: CVE-2026-38992 Coc… http://infoflow.cloud`

    Post summary

    The statement discloses that CVE‑2026‑38992 enables arbitrary code execution in Cockpit through a filter parameter, but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    0000020
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-38992 Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run… https://www.cve.org/CVERecord?id=CVE-2026-38992

    Post summary

    The text announces that CVE-2026-38992 enables arbitrary code execution through the filter parameter in multiple endpoints of Cockpit v2.13.5 and earlier.

    00000141
    57.3K followersView on X

Explore more