Ghostwire

CVE-2026-38993: Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows...

MEDIUM CVSS 5.5

Published: April 29, 2026 | Last Modified: April 29, 2026

Description

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References