PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105217 cockpit-hq CVE debrief

CVE-2026-105217 is a vulnerability in Cockpit CMS versions 2.12.0 before 2.14.1, where TLS certificate verification is disabled in the cron.php web worker restart request. This allows network attackers to capture the worker token via a man-in-the-middle attack. The vulnerability has a CVSS score of 2.3 and is considered low severity. Defenders should prioritize verifying affected versions, assessing exposure, and implementing proper TLS certificate verification. The vulnerability affects Cockpit CMS installations, particularly those using versions 2.12.0 to 2.14.0.

Vendor
cockpit-hq
Product
cockpit
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for Cockpit CMS installations, particularly those using versions 2.12.0 to 2.14.0, should assess exposure and prioritize verification and remediation. This includes reviewing compensating controls, monitoring for potential attacks, and tracking exceptions. The vulnerability has a CVSS score of 2.3 and is considered low severity.

Why it matters

CVE-2026-105217 is a vulnerability in Cockpit CMS that allows network attackers to capture the worker token via a man-in-the-middle attack. Defenders should prioritize verifying affected versions, assessing exposure, and implementing proper TLS certificate verification.

  • Potential token capture via man-in-the-middle attack.
  • Verification of affected versions and exposure is required.
  • Implementing proper TLS certificate verification is necessary.

Technical summary

The vulnerability is caused by disabled TLS certificate verification in the cron.php web worker restart request, allowing attackers to capture the worker token. This is a low-severity vulnerability with a CVSS score of 2.3. The vulnerability affects Cockpit CMS versions 2.12.0 before 2.14.1. Defenders should prioritize verifying affected versions, assessing exposure, and implementing proper TLS certificate verification. The CVE record was published on 2026-10-04T18:16:34.433Z and has not been modified since then. The source of this information is the CVE Program and the NIST National Vulnerability Database.

Defensive priority

Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability allows for potential token capture.

Recommended defensive actions

  • Verify if the system uses Cockpit CMS version 2.12.0 to 2.14.0 and apply version 2.14.1 or later if available.
  • Implement proper TLS certificate verification for the cron.php web worker restart request.
  • Monitor for potential man-in-the-middle attacks on the outbound path to site_url.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is caused by disabled TLS certificate verification in the cron.php web worker restart request. This allows attackers to present any certificate and steal the worker/web/token value. The vulnerability has a CVSS score of 2.3 and is considered low severity. The CVE record was published on 2026-10-04T18:16:34.433Z and has not been modified since then. The source of this information is the CVE Program and the NIST National Vulnerability Database.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105217 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105217

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105217 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105217

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.