CVE-2026-34965
Last modified
CVE-2026-34965 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP code through rule parameters which is written directly to server-side PHP files and executed via include() to achieve arbitrary command execution on the underlying server.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP code through rule parameters which is written directly to server-side PHP files and executed via include() to achieve arbitrary command execution on the underlying server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-34965?
How severe is CVE-2026-34965?
How do I fix CVE-2026-34965?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34956A flaw was found in Open vSwitch. When Open vSwitch is confi…5.9
- CVE-2026-3496The JetBooking plugin for WordPress is vulnerable to SQL Inj…7.5
- CVE-2026-34960barebox prior to version 2026.04.0 contains an out-of-bounds…7.1
- CVE-2026-34961barebox prior to version 2026.04.0 contains out-of-bounds re…7.7
- CVE-2026-34962barebox version prior to 2026.04.0 contains a denial-of-serv…5.5
- CVE-2026-34963barebox version prior to 2026.04.0 contains multiple memory-…7.8
- CVE-2026-34966Gitea prior to 1.27.0 contains a server-side request forgery…8.3
- CVE-2026-34969Nhost is an open source Firebase alternative with GraphQL. P…7.5
- CVE-2026-3497Vulnerability in the OpenSSH GSSAPI delta included in variou…7.5
- CVE-2026-34970Mantis Bug Tracker (MantisBT) is an open source issue tracke…5.3
- CVE-2026-34971Wasmtime is a runtime for WebAssembly. From 32.0.0 to before…9
- CVE-2026-34972OpenFGA is a high-performance and flexible authorization/per…8.8
Are you affected by CVE-2026-34965?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
