Cockpit CMS disclosed two high-severity vulnerabilities affecting versions earlier than 2.14.0, including a missing authorization flaw in the Bucket file storage API tracked as CVE-2026-57855. The issue in /system/buckets/api stemmed from the api() method in modules/System/Controller/Buckets.php, which executed bucket commands without enforcing ACL or role checks. As a result, any authenticated user, including low-privilege editors or content managers, could list files, upload content, delete files, rename objects, and create folders in arbitrary buckets, including administrator-only storage areas.
The advisory also described a path traversal flaw in bucket name handling that allowed ../ sequences to escape intended bucket directories, further expanding the risk of unauthorized file access and manipulation. Cockpit CMS said both vulnerabilities were fixed in version 2.14.0, released after coordinated disclosure with VulnCheck, and the authorization bug was rated high severity with a CVSS 3.1 score of 8.8 and mapped to CWE-284.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Cockpit CMS publicly disclosed the broken access control and path traversal vulnerabilities after coordinated disclosure via VulnCheck. The disclosure stated that low-privilege authenticated users could access or manipulate files outside their authorized bucket scope.
The missing authorization vulnerability in Cockpit CMS's Bucket file storage API was published as CVE-2026-57855. The issue allows any authenticated user to perform bucket operations without ACL or role checks, including against admin-only buckets.
Cockpit CMS fixed the broken access control issue in the Buckets API in version 2.14.0. The advisory says versions earlier than 2.14.0 were affected and that the release also fixed a related path traversal issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegist.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.