CVE-2026-4802Disclosure

MEDIUMCVSS 8.0 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-11); latest day: 2
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-05-11: 4Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-20: 2PoC Mentioned / Linked · 2026-05-20: 1Exploit Tool / Code · 2026-05-20: 1Patch / Workaround · 2026-05-11: 2Technical Details · 2026-05-11: 4Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-20: 205-1105-1305-1405-20
Signal classification4 categories
Disclosure
450.0%
General
225.0%
Patch
112.5%
PoC
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-114
Disclosure2General1Patch1
2026-05-131
Disclosure1
2026-05-141
General1
2026-05-202
Disclosure1PoC1
Full discourse8 posts
  • Hakai Offsec@HakaiOffsec
    Disclosure

    In our latest analysis, we dive into CVE-2026-4802, a high-severity vulnerability discovered by our team in Cockpit that allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). Read the full analysis on our blog: https://hakaisecurity.io/en-cve-2026-4802-command-execution-on-cockpit/research-blog/

    Post summary

    The post outlines a newly discovered high‑severity remote command execution flaw in Cockpit, detailing the vulnerability’s mechanics but not providing exploits, patches, or evidence of active use.

    02511005811.4K
    1.2K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4802: Cockpit: Arbitrary code execution in the logs page via a specially crafted link https://www.openwall.com/lists/oss-security/2026/05/20/19 can inject shell metacharacters and command substitutions. The exploit requires the user to be logged in to Cockpit.

    Post summary

    The advisory discloses an arbitrary code execution flaw in Cockpit’s logs page via a crafted link, providing technical details but no PoC, exploit code, active exploitation evidence, or patch information.

    00071663
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Technical details and a functional Python PoC exploit have been released for a critical Cockpit flaw giving low-privilege users root. #LinuxSecurity #CockpitRCE #CVE #RedHat #SysAdmin #InfoSec #VulnerabilityAlert #PoCExploit https://securityonline.info/cockpit-linux-rce-vulnerability-cve-2026-4802-poc-disclosed/ https://t.co/lceKRADGK2

    Post summary

    A functional Python PoC has been released for the Cockpit RCE vulnerability (CVE-2026-4802), granting low‑privilege users root access. No active exploitation or patch information is included.

    00053844
    12.5K followersView on X
  • ROHAN@takkerohan97
    General

    Remote execution on cockpit (CVE-2026-4802) The vulnerability allows arbitrary command execution on the host via crafted links in the system logs UI caused by unsanitized user-controlled parameters. Technical breakdown: https://hakaisecurity.io/en-cve-2026-4802-command-execution-on-cockpit/research-blog/

    Post summary

    The post outlines an RCE vulnerability (CVE-2026-4802) in Cockpit caused by unsanitized URL parameters, but does not provide a PoC, exploitation tool, evidence of active attacks, or patch information.

    00030161
    350 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4802 A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled pa… https://www.cve.org/CVERecord?id=CVE-2026-4802

    Post summary

    The text announces CVE‑2026‑4802, a remote command‑execution flaw in Cockpit caused by unsanitized user‑controlled input, but it does not include a PoC, exploit, patch, or evidence of active exploitation.

    00000138
    57.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Cockpit Command Injection via Logs UI (CVE-2026-4802) Cockpit contains a vulnerability where unsanitized user-controlled parameters in crafted links within the system logs UI can lead to command injection. An attacker can inject shell metacharacters to execute arbitrary commands on the host. This may result in remote code execution and full system compromise. 👉 Affected: Cockpit | Fix: Monitor vendor advisory for updates

    Post summary

    A high‑severity command injection flaw (CVE‑2026‑4802) in Cockpit allows remote code execution via the logs UI; patching is advised by monitoring vendor advisories.

    0000076
    187 followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 Entity detected CVE-2026-4802 in Cockpit. Remote attackers achieve arbitrary command execution through unsanitized parameters in system logs UI. Shell metacharacters bypass input validation. Complete system compromise probable. Patch immediately. https://0x2ed3bb60.xyz/threa...

    Post summary

    CVE‑2026‑4802 allows remote arbitrary command execution through unsanitized logs UI parameters in Cockpit; immediate patching is required to prevent full system compromise.

    0000018
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4802 Remote Command Execution in Cockpit via Unsanitized System Logs UI Parameters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4802

    Post summary

    CVE-2026-4802 is a remote command execution flaw in Cockpit that arises from unsanitized system logs UI parameters; the brief note points to a vulnerability details page but provides no PoC, exploit code, or patch information.

    0000054
    4.0K followersView on X

Explore more