# CVE-2026-58467: Cockpit - Path Traversal

> Live exploitation tracking for CVE-2026-58467 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-58467

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 8.2
- **Public exploit available:** Yes
- **Affected products:** Cockpit-HQ Cockpit
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** cms

## Description

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations.

## CrowdSec analysis

[CVE-2026-58467](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-58467) is a high-severity path traversal and local file inclusion vulnerability in Cockpit CMS through version 2.14.0. Unauthenticated remote attackers can use crafted dot-dot URL sequences to read arbitrary files outside the intended directory and, under certain server configurations, execute local PHP files, potentially exposing sensitive data or enabling further compromise.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec network observations suggest that most exploitation of CVE-2026-58467 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental.
CrowdSec data also reveals a clear uptick in attacks involving CVE-2026-58467 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.

Attackers target Cockpit CMS routes beginning with `/:` and containing `/storage/`, using repeated `../` path traversal sequences to escape the intended directory and access local files such as `/etc/passwd`.

## Timeline

- 2026-07-02: CVE Published. CVE-2026-58467 is published to NVD.
- 2026-10-05: Rule Released. CrowdSec releases a rule to detect CVE-2026-58467 exploitation attempts against the CrowdSec Network.
- 2026-10-07: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-58467 for the first time.

## References

- https://github.com/geo-chen/oss/blob/main/cockpit.md
- https://www.vulncheck.com/advisories/cockpit-cms-path-traversal-local-file-inclusion-via-index-php
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-58467.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-58467) follows observed exploitation activity for CVE-2026-58467. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
