CVE-2018-10931: Cobbler Project Cobbler

Critical severity, CVSS 9.8. EPSS: 68.1% chance of exploitation in the next 30 days.

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

Affected products

  • Cobbler Project Cobbler: from 2.6.0, up to and including 2.6.11
  • Red Hat Satellite: version 5.6 only; version 5.7 only; version 5.8 only

Published 2018-08-09. Last modified 2026-06-17.