Sceawere

Vulnerability Detail

CVE-2026-105217UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cockpit CMS TLS Verification Bypass

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
1d ago
Vendor
cockpit-hq
Product
cockpit
Attack Type
Improper Certificate Validation
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-04T18:16:34.433Z",
  "pubdate": "2026-10-04T18:16:34.433Z",
  "executiveSummary": "Cockpit CMS versions 2.12.0 through 2.14.0 contain a critical security vulnerability involving the improper implementation of TLS certificate validation within the cron.php web worker restart mechanism.\nThe vulnerability allows for Man-in-the-Middle (MitM) attacks during the outbound request process to the defined site_url.\nBy failing to verify the authenticity of the server's TLS certificate, the application becomes susceptible to traffic interception, enabling an attacker to capture sensitive worker tokens.\nSuccessful exploitation grants an unauthorized network attacker the ability to hijack the worker token, potentially leading to the unauthorized initiation of web worker processes.\nThis vulnerability highlights a failure in secure communication protocols, exposing internal system operations to external actors positioned on the network path between the Cockpit instance and the target URL.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure configuration of the HTTP client used within the cron.php file to trigger web worker restarts. In the affected versions (2.12.0 to 2.14.0), the request execution logic explicitly disables TLS certificate verification.\nWhen Cockpit CMS initiates a request to the configured site_url to manage web worker states, the underlying library performs the outbound network call without validating the identity of the destination server against a trusted Certificate Authority (CA). This effectively renders the HTTPS connection insecure, as it cannot guarantee the integrity or origin of the server response.\nThe attack flow follows a classic MitM paradigm. An attacker positioned on the network segment between the Cockpit server and the target site_url can intercept the outbound request. Since the application does not perform server certificate validation, the attacker can present an arbitrary or self-signed certificate, which the client will accept as legitimate.\nDuring the initiation of the handshake, the vulnerable cron.php routine transmits a sensitive 'worker/web/token' value. Because the connection is not cryptographically bound to a verified identity, this token is disclosed in transit to the intercepting entity.\nOnce the attacker successfully captures the token, they possess the credentials required to interact with the web worker interface. Consequently, the attacker can leverage the stolen token to issue command requests, such as the unauthorized restart or manipulation of web workers.\nThe impact is significant as it allows for unauthorized control over background worker processes. This exploitation requires the attacker to have network-level proximity or control—such as through DNS spoofing, ARP poisoning, or routing compromise—to intercept traffic directed to the site_url.\nThis vulnerability demonstrates a critical deficiency in secure network programming practices, specifically the reliance on insecure transport configurations for inter-process or inter-server communication within the Cockpit CMS architecture."
}
CVE-2026-105217: Cockpit CMS TLS Verification Bypass (LOW Severity, CVSS: 3.1) | Sceawere