Alerts This Week
Warning Icon 1 500
Alerts This Week
Warning Icon 1 500

Fedora 44 Cockpit 362 Security Advisory CVE-2026-4802 Arbitrary Execution

fedora
Calendar Grey May 21, 2026
Dist Fedora Esm H88
Update addresses critical arbitrary code execution in Cockpit 362 for Fedora 44; immediate action is recommended.
Automatic update for cockpit-362-1.fc44

Summary

The Cockpit Web Console enables users to administer GNU/Linux servers using a

web browser.

It offers network configuration, log inspection, diagnostic reports, SELinux

troubleshooting, interactive command-line sessions, and more.

Update Information:

Automatic update for cockpit-362-1.fc44. Changelog for cockpit * Wed May 20 2026 Packit - 362-1 - Bug fixes and translation updates - Fix arbitrary code execution via specially crafted logs page link (CVE-2026-4802)

Change Log

* Wed May 20 2026 Packit - 362-1 - Bug fixes and translation updates - Fix arbitrary code execution via specially crafted logs page link (CVE-2026-4802)

References


[ 1 ] Bug #2480095 - [Exploits (KEV)] CVE-2026-4802 cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480095

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ac9d9c87c8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: cockpit
Product: Fedora 44
Version: 362
Release: 1.fc44
Summary: Web Console for Linux servers

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here