CVE-2026-72557: Cockpit CMS

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server.

Affected products

Published 2026-08-11. Last modified 2026-09-03.