Cockpit - Path Traversal (CVE-2026-58467)
Description
Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.
psychologyCrowdSec Analysis
CVE-2026-58467 is a high-severity path traversal and local file inclusion vulnerability in Cockpit CMS through version 2.14.0. Unauthenticated remote attackers can use crafted dot-dot URL sequences to read arbitrary files outside the intended directory and, under certain server configurations, execute local PHP files, potentially exposing sensitive data or enabling further compromise.
CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-58467 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers target Cockpit CMS routes beginning with /: and containing /storage/, using repeated ../ path traversal sequences to escape the intended directory and access local files such as /etc/passwd.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-07-02 |
| Rule Released | 2026-10-05 |