CVE-2026-72557: Cockpit CMS
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server.
Affected products
- Cockpit CMS Cockpit CMS: up to and including 2.6.0
Published 2026-08-11. Last modified 2026-09-03.