RHSA-2026:7382: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Published Apr 10, 2026
·Updated
Cockpit enables users to administer GNU/Linux servers using a web browser. Itoffers network configuration, log inspection, diagnostic reports, SELinuxtroubleshooting, interactive command-line sessions, and more.Security Fix(es): cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Other sources
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
— Red Hat
Affected Software
37 affected componentsFixes available
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Red Hat Enterprise Linux for ARM 64 - 4 years of updates
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Life Cycle
Red Hat Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux for IBM z Systems - 4 years of updates
Red Hat Red Hat Enterprise Linux Server - AUS
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Update Support
redhat/cockpit<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-bridge<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-debuginfo<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-debugsource<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-doc<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-packagekit<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-storaged<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-system<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-ws<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-bridge<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-debuginfo<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-debugsource<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-ws<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-bridge<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-debuginfo<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-debugsource<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit-ws<334.2-2.el9_6
334.2-2.el9_6
redhat/cockpit<334.2-2.el9_6.aa
334.2-2.el9_6.aa
redhat/cockpit-bridge<334.2-2.el9_6.aa
334.2-2.el9_6.aa
redhat/cockpit-debuginfo<334.2-2.el9_6.aa
334.2-2.el9_6.aa
redhat/cockpit-debugsource<334.2-2.el9_6.aa
334.2-2.el9_6.aa
redhat/cockpit-ws<334.2-2.el9_6.aa
334.2-2.el9_6.aa
Remediation
Event History
Apr 10, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Advisory Published
via Red Hat·02:01 PM
Data Sourced
via Red Hat·02:01 PM
Severity