PatchSiren cyber security CVE debrief
CVE-2026-105217 cockpit-hq CVE debrief
CVE-2026-105217 is a vulnerability in Cockpit CMS versions 2.12.0 before 2.14.1, where TLS certificate verification is disabled in the cron.php web worker restart request. This allows network attackers to capture the worker token via a man-in-the-middle attack. The vulnerability has a CVSS score of 2.3 and is considered low severity. Defenders should prioritize verifying affected versions, assessing exposure, and implementing proper TLS certificate verification. The vulnerability affects Cockpit CMS installations, particularly those using versions 2.12.0 to 2.14.0.
- Vendor
- cockpit-hq
- Product
- cockpit
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for Cockpit CMS installations, particularly those using versions 2.12.0 to 2.14.0, should assess exposure and prioritize verification and remediation. This includes reviewing compensating controls, monitoring for potential attacks, and tracking exceptions. The vulnerability has a CVSS score of 2.3 and is considered low severity.
Why it matters
CVE-2026-105217 is a vulnerability in Cockpit CMS that allows network attackers to capture the worker token via a man-in-the-middle attack. Defenders should prioritize verifying affected versions, assessing exposure, and implementing proper TLS certificate verification.
- Potential token capture via man-in-the-middle attack.
- Verification of affected versions and exposure is required.
- Implementing proper TLS certificate verification is necessary.
Technical summary
The vulnerability is caused by disabled TLS certificate verification in the cron.php web worker restart request, allowing attackers to capture the worker token. This is a low-severity vulnerability with a CVSS score of 2.3. The vulnerability affects Cockpit CMS versions 2.12.0 before 2.14.1. Defenders should prioritize verifying affected versions, assessing exposure, and implementing proper TLS certificate verification. The CVE record was published on 2026-10-04T18:16:34.433Z and has not been modified since then. The source of this information is the CVE Program and the NIST National Vulnerability Database.
Defensive priority
Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability allows for potential token capture.
Recommended defensive actions
- Verify if the system uses Cockpit CMS version 2.12.0 to 2.14.0 and apply version 2.14.1 or later if available.
- Implement proper TLS certificate verification for the cron.php web worker restart request.
- Monitor for potential man-in-the-middle attacks on the outbound path to site_url.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is caused by disabled TLS certificate verification in the cron.php web worker restart request. This allows attackers to present any certificate and steal the worker/web/token value. The vulnerability has a CVSS score of 2.3 and is considered low severity. The CVE record was published on 2026-10-04T18:16:34.433Z and has not been modified since then. The source of this information is the CVE Program and the NIST National Vulnerability Database.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105217 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105217
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105217 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105217
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Cockpit-HQ/Cockpit
-
Source reference
Unverified legacy reference
URL: https://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/cron.php
-
Source reference
Unverified legacy reference
URL: https://github.com/Cockpit-HQ/Cockpit/commit/c611492adc17362578faa97f9c30b41e6c16e040
-
Source reference
Unverified legacy reference
URL: https://github.com/Cockpit-HQ/Cockpit/issues/318
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/cockpit-cms-2.12.0-before-2.14.1-disabled-tls-verification-via-cron-php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.