RHSA-2026:7384: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Cockpit enables users to administer GNU/Linux servers using a web browser. Itoffers network configuration, log inspection, diagnostic reports, SELinuxtroubleshooting, interactive command-line sessions, and more.Security Fix(es): cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Other sources
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/cockpitto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-bridgeto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-debuginfoto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-debugsourceto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-docto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-packagekitto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-storagedto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-systemto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-wsto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpit-ws-selinuxto a version that resolves this vulnerability.Fixed in 344-2.el9_7 - Upgrade
Upgrade
redhat/cockpitto a version that resolves this vulnerability.Fixed in 344-2.el9_7.aa - Upgrade
Upgrade
redhat/cockpit-debuginfoto a version that resolves this vulnerability.Fixed in 344-2.el9_7.aa - Upgrade
Upgrade
redhat/cockpit-debugsourceto a version that resolves this vulnerability.Fixed in 344-2.el9_7.aa - Upgrade
Upgrade
redhat/cockpit-wsto a version that resolves this vulnerability.Fixed in 344-2.el9_7.aa - Upgrade
Upgrade
redhat/cockpit-ws-selinuxto a version that resolves this vulnerability.Fixed in 344-2.el9_7.aa - Upgrade
Upgrade
cockpitto a version that resolves this vulnerability.Patch CVE-2026-4631
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:7384?
RHSA-2026:7384 is classified as critical due to potential unauthenticated remote code execution.
How do I fix RHSA-2026:7384?
To mitigate RHSA-2026:7384, update the cockpit package to version 344-2.el9_7.
Which platforms are affected by RHSA-2026:7384?
RHSA-2026:7384 affects Red Hat Enterprise Linux for IBM z Systems, x86_64, ARM 64, and Power little endian.
What specific package versions are involved in RHSA-2026:7384?
The affected packages include cockpit and cockpit-bridge, with the remedy being version 344-2.el9_7.
Is user authentication required for the vulnerability in RHSA-2026:7384?
No, RHSA-2026:7384 allows unauthenticated remote code execution, making it particularly dangerous.