← לוח פגיעויות

CVE-2026-38993

בינונית 6.5

תיאור (מקור, אנגלית)

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-27/9/2026
CWE
CWE-22

קישורים