CVE-2026-4631 is an OS command injection vulnerability in Cockpit's cockpit-ws remote-login authentication flow. Cockpit passes user-controlled hostnames and usernames to an OpenSSH invocation without adequate validation or sanitization before credential verification completes. The SSH command construction lacks a -- separator before the destination argument, enabling hostname-based SSH option injection on affected OpenSSH versions. A separate username-based path may permit shell-command injection where the local SSH configuration uses the %r token in a Match exec directive. The issue affects Cockpit versions later than 326 and was fixed in Cockpit 360.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
LoginTo=false and disable multi-host access by setting AllowMultiHost=false. Restrict cockpit-ws binding and firewall access so that only trusted administrative networks can reach the Cockpit service. Updating OpenSSH to 9.6 or later mitigates the hostname-based injection path, but configurations that use %r in SSH Match exec directives should also be reviewed and removed or hardened.Patch, then assume compromise.
-- separator before the SSH destination argument and enforce allowlist-based validation of usernames and hostnames before they are passed to the SSH client. Update OpenSSH to version 9.6 or later as additional defense against the described hostname-based command-line injection path, while recognizing that this does not replace the Cockpit fix.2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a standalone Python mass exploitation tool for CVE-2026-4631, an unauthenticated pre-auth command injection/RCE flaw in Cockpit's remote login flow. It is not tied to a major exploit framework. The codebase is organized into a small CLI front end (`exploit.py`), a `core/` package implementing target normalization, vulnerability probing, exploit delivery, callback handling, and orchestration, plus `utils/` for banner/output helpers and `docs/` containing vulnerability, patch, detection, and targeting notes. Main capability: the tool can scan many targets concurrently for likely vulnerable Cockpit instances and then exploit them using one of two HTTP-triggered attack paths against the Cockpit web service on port 9090. The primary vector injects `-oProxyCommand=<cmd>` into the hostname portion of the `/cockpit+=.../login` path. The secondary vector injects shell metacharacters into the username field carried in the `Authorization: Basic` header. In exploit mode, the tool wraps the operator-supplied command in a Bash payload that runs the command, captures stdout/stderr, base64-encodes it, and sends it back to an attacker-controlled HTTP listener. Because the vulnerability is blind, the repository includes its own threaded callback server (`core/listener.py`) that listens on `0.0.0.0:8888` by default and correlates responses using a short request ID. Operational flow: `exploit.py` parses CLI options, loads targets from `-t` or `-f`, auto-adds port 9090 when absent, and selects `scan`, `auto`, or direct `rce` mode. `core/scanner.py` fingerprints Cockpit by requesting `/` and probing `/cockpit+=probe-host/login` with dummy Basic auth. `core/exploit.py` builds the exploit URL/header and sends the malicious request with TLS verification disabled. `core/engine.py` manages concurrency with a thread pool, starts the callback listener when needed, and records results to `results.txt`. The tool also attempts to detect when ProxyCommand injection may be blocked by OpenSSH 9.6+ and can automatically fall back to the username vector. Notable endpoints and artifacts: target-facing paths include `/`, `/cockpit+=probe-host/login`, `/cockpit+=-oProxyCommand=<payload>/login`, and `/cockpit+=localhost/login`. The attacker-side callback endpoint is `http://<callback_ip>:8888/cb?id=<reqid>`. Local artifacts include `targets.txt`, `results.txt`, and optional scan output files. Overall, this is a real operational exploit utility rather than a detector-only script: it supports mass targeting, threading, blind output exfiltration, vector fallback, and customizable commands, but the payloading is still relatively basic and hardcoded compared with a full exploitation framework.
Repository is a small standalone Python exploit/scan tool for CVE-2026-4631 affecting Cockpit 327-359. Structure is minimal: a detailed README describing the vulnerability and exploitation theory, one executable Python script (exploit.py), and an insignificant image placeholder file. The exploit is not part of a larger framework. The Python script uses requests to send crafted unauthenticated HTTP GET requests to Cockpit's login endpoint while supplying attacker-controlled values in either the URL path or the Basic Authorization header. It implements two exploit paths: (1) hostname vector, which places a malicious SSH option such as -oProxyCommand=<cmd> into the Cockpit path segment /cockpit+=.../login, and (2) username vector, which injects shell metacharacters into the Basic auth username as x; <command>; # while targeting an SSH host (default 127.0.0.1). The script treats HTTP 200/401/403/500 as evidence the request reached the vulnerable code path and also handles connection resets as a possible side effect of exploitation. Capabilities include direct command execution, time-based detection using sleep 5, out-of-band callback triggering via curl, reverse-shell command generation using bash /dev/tcp, and batch scanning from a file of URLs. TLS verification is explicitly disabled. The exploit does not contain a sophisticated staged payload or framework integration, but it is operational and supports practical exploitation workflows. Fingerprintable targets/endpoints are primarily the Cockpit login paths /cockpit+=-oProxyCommand=<command>/login and /cockpit+=<ssh_host>/login, default service port 9090, default SSH host 127.0.0.1, and local file url.txt for batch input. The README also documents mitigation via /etc/cockpit/cockpit.conf. Overall purpose: exploit or detect unauthenticated remote code execution in vulnerable Cockpit deployments by abusing unsafe argument passing to ssh.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical, network-accessible vulnerability identified as CVE-2026-4631, referenced by an AlmaLinux 9.6 local security-check plugin. The provided CVSS v3 vector indicates unauthenticated remote exploitation with high confidentiality, integrity, and availability impact.
A pre-authentication remote code execution vulnerability affecting Cockpit Web Console versions earlier than 360, apparently via SSH-related functionality.
An unauthenticated OS command injection in Cockpit's remote login feature that allows remote code execution on the host via a single HTTP request without credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.