CVE-2026-4631Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 16 signals
  • Disclosure: 10 classified signals
  • Peaked 10d ago at 5 mentions (2026-04-07); latest day: 1
  • 18 total mentions across 11 days

Deep dive

Activity timeline18 mentions / 11d
01345Mentions · 2026-04-07: 5Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 2Mentions · 2026-04-15: 2Mentions · 2026-04-16: 2Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-05-24: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-18: 1Exploit Tool / Code · 2026-04-13: 1Exploit Tool / Code · 2026-04-18: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-07: 5Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 2Technical Details · 2026-04-18: 1Technical Details · 2026-05-24: 104-0704-1004-1104-1304-1404-1504-1604-1804-1904-2005-24
Signal classification4 categories
Disclosure
1055.6%
Exploit
316.7%
Patch
316.7%
General
211.1%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-04-075
Disclosure3Exploit1Patch1
2026-04-101
Patch1
2026-04-111
Disclosure1
2026-04-131
Exploit1
2026-04-142
Disclosure1Patch1
2026-04-152
Disclosure2
2026-04-162
Disclosure2
2026-04-181
Exploit1
2026-04-191
General1
2026-04-201
General1
2026-05-241
Disclosure1
Full discourse18 posts
  • abdelazim (PikaChu)@intx0x80
    Exploit

    CVE-2026-4631 cockpit Unauthenticated remote code We successfully developed a full exploit along with an automated scanner to efficiently identify vulnerable servers at scale. POC+vulnerability analysis will published soon https://t.co/gCm2yJuRVH

    Post summary

    The post announces that a full exploit and automated scanner for CVE-2026-4631 have been implemented, with a PoC and analysis expected soon, but no patch or active exploitation evidence is provided.

    3173114577.9K
    2.2K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-4631(CVSS 9.8):Critical RCE Flaw in Cockpit Allows Unauthenticated Server Takeover. 📊 1.3M Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cockpit%22 👇Query HUNTER : http://product.name="Cockpit" 📰Refer:https://securityonline.info/cockpit-rce-vulnerability-linux-security-cve-2026-4631/ https://www.openwall.com/lists/oss-security/2026/04/10/5 https://github.com/cockpit-project/cockpit/security/advisories/GHSA-m4gv-x78h-3427 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The alert announces CVE‑2026‑4631, a critical remote code execution flaw in Cockpit, providing its CVSS score and links to advisory resources.

    117138244.4K
    25.9K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-4631 (CVSS 9.8): Cockpit remote login flaw may allow unauthenticated SSH option injection and code execution on the host. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDb2NrcGl0LU9TLU1hbmdlciI= 🎯242.3K+ Results are found on http://en.fofa.info. FOFA Query: app="Cockpit-OS-Manger" 🔖Refer: https://securityonline.info/cockpit-rce-vulnerability-linux-security-cve-2026-4631/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces the CVE-2026-4631 Cockpit remote login flaw with technical details, but does not provide PoC, exploit code, or patch information.

    012033183.2K
    14.3K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    A Cockpit SSH argument injection RCE vulnerability (CVE-2026-4631) allows unauthenticated remote code execution via ProxyCommand or username injection. https://www.redsecuretech.co.uk/blog/post/cockpit-ssh-argument-injection-rce-affects-versions-327-359/1202 #Cockpit #CVE #SSHInjection #RCE #ProxyCommand #UsernameInjection #OpenSSH #ReverseShell #InfoSec https://t.co/YRKmPJknkW

    Post summary

    The post announces the discovery of a new remote code execution flaw (CVE-2026-4631) in Cockpit’s SSH handling, detailing its injection vector via ProxyCommand or username injection, without indicating exploit code, active attacks, or patches.

    09027102.1K
    69 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Cockpit CVE-2026-4631 allows unauthenticated RCE on Linux servers via SSH injection. Stop the unauthorized takeover—upgrade to Cockpit version 360 now! #Cockpit #LinuxSecurity #RCE #InfoSec #CyberSecurity #SysAdmin #ServerHardening https://securityonline.info/cockpit-rce-vulnerability-linux-security-cve-2026-4631/ https://t.co/pV7ynQF7gZ

    Post summary

    The post advertises that Cockpit CVE-2026-4631 allows unauthenticated RCE through SSH injection and urges users to upgrade to version 360 to mitigate the issue.

    071167707
    12.3K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4631: Cockpit: Unauthenticated remote code execution due to SSH command-line argument injection https://www.openwall.com/lists/oss-security/2026/04/10/5 passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. CVSS 9.8.

    Post summary

    The post discloses CVE-2026-4631, a high‑severity (CVSS 9.8) unauthenticated RCE flaw in Cockpit caused by SSH command‑line injection, but offers no PoC, exploit, patch, or active‑exploitation evidence.

    170821.7K
    4.6K followersView on X
  • abdelazim (PikaChu)@intx0x80
    Exploit

    CVE-2026-4631: Cockpit: Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection exploit and technical analysis https://github.com/cyberheartmi9/CVE-2026-4631-cockpit-RCE

    Post summary

    A GitHub repo is linked, providing a functional exploit and analysis for CVE‑2026‑4631, confirming unauthenticated remote code execution via SSH command injection.

    00102565
    2.2K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-4631 - critical 🚨 Cockpit Web Console < 360 - Remote Code Execution > Cockpit's remote login feature passes user-supplied hostnames and usernames from the ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-4631 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑4631 as a critical remote code execution flaw in Cockpit Web Console, providing only a concise description and a link for more information, but it does not disclose a PoC, exploit, patch, or evidence of active exploitation.

    00003229
    930 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-33829 2 - CVE-2026-33826 3 - CVE-2026-39813 4 - CVE-2026-30898 5 - CVE-2026-4631 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVE identifiers, providing no additional technical or operational details.

    00011172
    1.7K followersView on X
  • abdelazim (PikaChu)@intx0x80
    General

    Cockpit RCE CVE-2026-4631 #CVE

    Post summary

    The text merely lists the CVE identifier without providing additional context or details.

    00020245
    2.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4631 — CVSS 9.8/10 ██████████ Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/mlGeC3py1i

    Post summary

    A critical Cockpit remote login vulnerability (CVE‑2026‑4631) has been disclosed with an available patch.

    1000097
    16 followersView on X
  • Grok@grok
    Disclosure

    CVE-2026-4631 是 Cockpit(Linux Web 管理面板)中的严重远程代码执行漏洞,CVSS 9.8 分数,允许未授权服务器接管。 **成因**:Cockpit 的远程登录功能(SSH 桥接)将用户输入的主机名和用户名直接传给 SSH 客户端,未做验证或过滤。攻击者可通过单次 HTTP 请求到登录端点,注入恶意 SSH 参数(如 -oProxyCommand)或 shell 命令。 **关键点**: - 攻击发生在认证前,无需任何凭证或登录。 - 只需网络能访问 Cockpit 服务(默认端口 9090)。 - 1.3M+ 服务暴露,风险高。 **受影响**:Cockpit 327+ 版本 + OpenSSH <9.6 的默认配置。 **修复**:升级 Cockpit 到最新版,启用 OpenSSH 9.6+(它会验证主机名阻挡注入)。关闭不必要的 Cockpit 暴露,检查防火墙。 详情见 Red Hat 公告:https://access.redhat.com/security/cve/cve-2026-4631

    Post summary

    CVE-2026-4631 is a critical remote code execution flaw in Cockpit, with a CVSS score of 9.8, impacting versions 327 and older when paired with OpenSSH <9.6. Patching to newer Cockpit releases and upgrading OpenSSH to 9.6+ addresses the issue.

    00000123
    8.7M followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-4631: Cockpitにおける重大な9.8 RCE脆弱性により、認証なしでサーバーを乗っ取ることができる CVE-2026-4631: Critical 9.8 RCE Flaw in Cockpit Allows Unauthenticated Server Takeover #DailyCyberSecurity (Apr 14) https://securityonline.info/cockpit-rce-vulnerability-linux-security-cve-2026-4631/

    Post summary

    The post announces the discovery of a critical 9.8 RCE vulnerability (CVE-2026-4631) in Cockpit, allowing unauthenticated server takeover. No PoC, exploit code, or patch details are provided.

    00000364
    4.8K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-4631 (CVSS 9.8) - Cockpit remote login allows unauthenticated RCE via SSH command injection. No credentials needed. Patch immediately if you run Cockpit web service. #CVE #PatchNow #ThreatIntel https://t.co/HEjpomMJjQ

    Post summary

    CVE‑2026‑4631 enables unauthenticated remote code execution on Cockpit via SSH command injection; users of the service should apply the available patch immediately.

    00000103
    10 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4631: CRITICAL] Weak remote login implementation in Cockpit allows attackers to inject malicious SSH options or shell commands, leading to unauthorized code execution without valid credentials. #Cybe...#cve,CVE-2026-4631,#cybersecurity https://cvefind.com/CVE-2026-4631

    Post summary

    The tweet announces a critical Cockpit remote‑login flaw that permits SSH option or shell command injection for code execution without credentials, with no PoC, exploit, patch, or active exploitation details provided.

    0000082
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker wit… https://www.cve.org/CVERecord?id=CVE-2026-4631 ----- Traducción: CVE-2026-4631 La … http://infoflow.cloud`

    Post summary

    The tweet discloses vulnerability CVE-2026-4631 in Cockpit’s remote‑login feature, detailing unchecked user input sent to SSH, but contains no PoC, exploit code, active‑exploitation evidence, patch information, or false‑positive claim.

    0000067
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker wit… https://www.cve.org/CVERecord?id=CVE-2026-4631

    Post summary

    The text announces CVE-2026-4631, describing a flaw in Cockpit’s remote login that forwards unsanitized hostnames and usernames to the SSH client, providing basic vulnerability details without any exploit, patch, or active exploitation evidence.

    00000172
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-4631: Cockpit: cockpit: unauthenticated... SSH argument injection in Cockpit's login flow bypasses auth entirely - craft one HTTP request, own the box via maliciou... https://zerodaysignal.com/vulnerability/CVE-2026-4631 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The note warns of a new unauthenticated vulnerability in Cockpit’s SSH login; an attacker can send a crafted HTTP request to gain control, with more details likely on the linked ZeroDaySignal page.

    00000101
    204 followersView on X

Explore more