CVE-2026-105217: Cockpit-Hq Cockpit

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.

Affected products

  • Cockpit-Hq Cockpit: from 2.12.0, before 2.14.1 (fixed in 2.14.1)

Published 2026-10-04. Last modified 2026-10-06.