CVE-2026-4802 is an OS command injection vulnerability in Cockpit's system logs user interface. Unsanitized user-controlled parameters in crafted links, including boot-descriptor-related parameters, can accept shell metacharacters and command substitutions. When Cockpit processes the crafted link, injected shell syntax can cause arbitrary shell commands to execute on the managed host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept exploit for CVE-2026-4802 targeting Cockpit on Linux. It contains three files: a Python exploit script (poc.py), a Dockerfile that builds a reproducible vulnerable Cockpit environment, and a README describing setup and usage. The exploit is not part of a larger framework. The main exploit logic is in poc.py. It first authenticates to the target Cockpit instance using HTTP Basic authentication against /cockpit/login and extracts the returned session cookie. It then upgrades to the Cockpit websocket endpoint at /cockpit/socket using the cockpit1 subprotocol, sends an init message, and opens websocket channels with payload type stream. Through these channels it requests command spawning on the remote host. The vulnerability is exploited by constructing a shell command that mimics the vulnerable loadServiceFilters() behavior: a journalctl invocation with a malicious --since=$(...) argument. The injected payload is wrapped in command substitution so that when /bin/bash -ec evaluates the command line, attacker-controlled shell commands execute. The script supports three modes: check, which writes id output to /tmp/cockpit-rce-check and reads it back to confirm RCE; exec, which redirects arbitrary command output to /tmp/.cockpit-rce-out and retrieves it; and reverse, which sends a bash reverse shell using /dev/tcp/<lhost>/<lport>. The Dockerfile provisions a Fedora-based Cockpit instance, creates a low-privileged viewer:viewer account, enables Cockpit on port 9090, and weakens configuration for testing by allowing unencrypted access and all origins in /etc/cockpit/cockpit.conf. This indicates the repository’s purpose is to demonstrate and validate the vulnerability in a lab environment rather than provide stealthy or large-scale exploitation tooling. Overall capability: authenticated remote code execution against vulnerable Cockpit instances, with command output retrieval and optional reverse shell callback. The exploit requires valid credentials and a reachable Cockpit service with the vulnerable logs UI code path present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability tracked as CVE-2026-4802, rated Important by the vendor, with high confidentiality, integrity, and availability impact under its listed CVSS v3 vector. The provided content does not identify the affected component or flaw type.
An Important-severity vulnerability tracked as CVE-2026-4802, addressed by an Alma Linux 9.6 security update. The supplied CVSS v3 vector indicates network attackability with low complexity, requiring low privileges and user interaction, with high impact to confidentiality, integrity, and availability.
A vulnerability affecting Cockpit on Debian 13 that, together with CVE-2026-76235, could enable arbitrary code execution or denial of service. Debian fixed the issue in cockpit version 337-1+deb13u2.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.