RHSA-2026:7381: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Published Apr 10, 2026
·Updated
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Affected Software
32 affected componentsFixes available
redhat/cockpit<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-bridge<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-debuginfo<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-debugsource<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-doc<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-packagekit<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-storaged<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-system<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-ws<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-bridge<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-debuginfo<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-debugsource<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-ws<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-bridge<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-debuginfo<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-debugsource<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit-ws<334.1-3.el10_0
334.1-3.el10_0
redhat/cockpit<334.1-3.el10_0.aa
334.1-3.el10_0.aa
redhat/cockpit-bridge<334.1-3.el10_0.aa
334.1-3.el10_0.aa
redhat/cockpit-debuginfo<334.1-3.el10_0.aa
334.1-3.el10_0.aa
redhat/cockpit-debugsource<334.1-3.el10_0.aa
334.1-3.el10_0.aa
redhat/cockpit-ws<334.1-3.el10_0.aa
334.1-3.el10_0.aa
Red Hat Red Hat Enterprise Linux for Power, little endian - 4 years of support
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for ARM 64 - 4 years of updates
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Red Hat Enterprise Linux for IBM z Systems - 4 years of updates
Red Hat Red Hat Enterprise Linux for x86_64 - 4 years of updates
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Remediation
Event History
Apr 10, 2026
Advisory Published
via Red Hat·02:00 PM
Data Sourced
via Red Hat·02:00 PM
DescriptionSeverityAffected Software
Apr 24, 2026
Advisory Published
via Red Hat·02:47 PM
Data Sourced
via Red Hat·02:47 PM
Remedy
Frequently Asked Questions
1
What is the severity of RHSA-2026:7381?
The severity of RHSA-2026:7381 is critical with a score of 9.
2
How do I fix RHSA-2026:7381?
To fix RHSA-2026:7381, apply the necessary update after ensuring all previously released errata relevant to your system have been applied.
3
What vulnerability does RHSA-2026:7381 address?
RHSA-2026:7381 addresses an unauthenticated remote code execution vulnerability due to SSH command-line argument injection.
4
Which software is affected by RHSA-2026:7381?
The affected software includes redhat/cockpit and its various components like cockpit-bridge, cockpit-debuginfo, and others.
5
When was RHSA-2026:7381 published?
RHSA-2026:7381 was published on April 10, 2026.