CVE-2026-105217: Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to siteurl can present any certificate to steal the worker/web/token value and start the web worker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cockpit CMSto a version that resolves this vulnerability.Fixed in 2.14.1
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Cockpit CMS versions 2.12.0 through versions before 2.14.1 are affected when cron.php performs the web worker restart request. An attacker must be able to intercept or alter network traffic on the outbound path to the configured site_url.
What does an attacker gain if exploitation succeeds?
A man-in-the-middle attacker can present an arbitrary TLS certificate, capture the worker token, and use that worker/web/token value to start the web worker.
What should be done if an immediate upgrade is not possible?
Limit the ability to intercept traffic between the host running cron.php and its configured site_url, since exploitation depends on a man-in-the-middle position on that outbound path. Upgrade to 2.14.1 or later when possible.