Hakai Offsec[verified]@HakaiOffsecDisclosure
The post outlines a newly discovered high‑severity remote command execution flaw in Cockpit, detailing the vulnerability’s mechanics but not providing exploits, patches, or evidence of active use.
Upwind Security MDR[verified]@UpwindMDRDisclosure
A high‑severity command injection flaw (CVE‑2026‑4802) in Cockpit allows remote code execution via the logs UI; patching is advised by monitoring vendor advisories.
Entity[verified]@0x2ed3bb60Patch
CVE‑2026‑4802 allows remote arbitrary command execution through unsanitized logs UI parameters in Cockpit; immediate patching is required to prevent full system compromise.
Open Source Security mailing list@oss_securityDisclosure
The advisory discloses an arbitrary code execution flaw in Cockpit’s logs page via a crafted link, providing technical details but no PoC, exploit code, active exploitation evidence, or patch information.
Gray Hats@the_yellow_fallPoC
A functional Python PoC has been released for the Cockpit RCE vulnerability (CVE-2026-4802), granting low‑privilege users root access. No active exploitation or patch information is included.
ROHAN@takkerohan97General
The post outlines an RCE vulnerability (CVE-2026-4802) in Cockpit caused by unsanitized URL parameters, but does not provide a PoC, exploitation tool, evidence of active attacks, or patch information.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑4802, a remote command‑execution flaw in Cockpit caused by unsanitized user‑controlled input, but it does not include a PoC, exploit, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
CVE-2026-4802 is a remote command execution flaw in Cockpit that arises from unsanitized system logs UI parameters; the brief note points to a vulnerability details page but provides no PoC, exploit code, or patch information.