tag
Cockpit
High
Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
CVE-2026-4802·
Red Hat Cockpit — the web-based Linux system administration console (cockpit-project.org), specifically pkg/systemd/logsJournal.jsx. **Not** to be confused with the headless "Cockpit CMS".
unpatched
Critical
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
CVE-2026-4631 (GHSA-m4gv-x78h-3427)·
Cockpit (Linux web-based server admin console)
patched