CVE-2026-39275: Cockpit CMS Cockpit CMS vulnerability
Published Aug 26, 2026
·Updated
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components.
Affected Software
1 affected component
Cockpit CMS Cockpit CMS<=2.13.5
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
Description
Frequently Asked Questions
1
Which Cockpit CMS versions are affected?
Cockpit CMS version 2.13.5 and earlier are identified as affected.
2
What components are implicated in the vulnerability?
The reported affected components are item.php, field-select.js, and tags.js.
3
What level of attacker access is described?
The issue is described as remotely exploitable; no additional authentication or privilege requirements are provided.