CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-58467Public Exploit

Cockpit - Path Traversal (CVE-2026-58467)

PublishedJul 2, 2026
First SeenOct 7, 2026
Last Seen
Reported
CVSS8.2
cms

Description

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.

psychologyCrowdSec Analysis

CVE-2026-58467 is a high-severity path traversal and local file inclusion vulnerability in Cockpit CMS through version 2.14.0. Unauthenticated remote attackers can use crafted dot-dot URL sequences to read arbitrary files outside the intended directory and, under certain server configurations, execute local PHP files, potentially exposing sensitive data or enabling further compromise.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-58467 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target Cockpit CMS routes beginning with /: and containing /storage/, using repeated ../ path traversal sequences to escape the intended directory and access local files such as /etc/passwd.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-07-02
Rule Released2026-10-05

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.