CVE-2026-58467Disclosure

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-02); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-02: 2Mentions · 2026-07-03: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 1Technical Details · 2026-09-22: 107-0207-0309-22
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-07-031
Patch1
2026-09-221
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-58467 - high 🚨 Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion > Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion (LFI) v... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-58467 @pdnuclei #NucleiTemplates #cve

    Post summary

    The text announces a Path Traversal/LFI vulnerability in Cockpit CMS 2.14.0 with technical details but does not confirm PoC availability, exploit tooling, patches, or active exploitation.

    11041525
    1.3K followersView on X
  • Mohi@disismohi
    Patch

    CVE-2026-58467: unauthenticated path traversal in Cockpit CMS becomes local file inclusion. Inject ../ in the URL, read arbitrary files, or execute PHP. Fixed in release 364.

    Post summary

    The post notes that Cockpit CMS CVE‑2026‑58467 allows unauthenticated path traversal leading to arbitrary file inclusion or PHP execution, and that the issue is fixed in release 364.

    1001055
    70 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58467 Cockpit CMS before release 364 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execu… https://www.cve.org/CVERecord?id=CVE-2026-58467 ----- Traducción: CVE-2026-58467 Coc… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑58467, describing its path traversal and LFI characteristics, but provides no PoC, exploit tool, active exploitation claim, or patch information.

    0000037
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58467 Cockpit CMS before release 364 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execu… https://www.cve.org/CVERecord?id=CVE-2026-58467

    Post summary

    The post discloses that Cockpit CMS editions before 364 contain a path traversal and local file inclusion vulnerability enabling unauthenticated file reads or execution, but no exploit or patch details are provided.

    00000623
    57.7K followersView on X

Explore more