2026-10-04 17:9CVE-2026-105217VulnCheck
PUBLISHED5.2CWE-295

Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.

Problem type

Affected products

cockpit-hq

cockpit

< 2.14.1 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-105217
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-105217",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-10-04T17:09:52.997Z",
    "dateReserved": "2026-10-04T13:04:00.478Z",
    "datePublished": "2026-10-04T17:09:52.997Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-10-04T17:09:52.997Z"
      },
      "datePublic": "2026-07-04T00:00:00.000Z",
      "title": "Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php",
      "descriptions": [
        {
          "lang": "en",
          "value": "Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker."
        }
      ],
      "affected": [
        {
          "vendor": "cockpit-hq",
          "product": "cockpit",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "2.12.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.14.1"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Improper Certificate Validation",
              "cweId": "CWE-295",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/Cockpit-HQ/Cockpit/issues/318",
          "name": "GitHub Issue #318",
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Cockpit-HQ/Cockpit/commit/c611492adc17362578faa97f9c30b41e6c16e040",
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/cron.php#L70-L102",
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/Cockpit-HQ/Cockpit",
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cockpit-cms-2.12.0-before-2.14.1-disabled-tls-verification-via-cron-php",
          "name": "VulnCheck Advisory: Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 3.1,
            "baseSeverity": "LOW"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Siyang Wu",
          "type": "finder"
        }
      ]
    }
  }
}