This update for cockpit fixes the following issues:
- CVE-2026-4802: Fixed a remote command execution via unsanitized
user-controlled parameters within crafted links in system logs UI
(boo#1265040).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-176=1
- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64):
cockpit-321-bp157.2.3.2
cockpit-bridge-321-bp157.2.3.2
cockpit-devel-321-bp157.2.3.2
cockpit-pcp-321-bp157.2.3.2
cockpit-ws-321-bp157.2.3.2
- openSUSE Backports SLE-15-SP7 (noarch):
cockpit-doc-321-bp157.2.3.2
cockpit-kdump-321-bp157.2.3.2
cockpit-networkmanager-321-bp157.2.3.2
cockpit-packagekit-321-bp157.2.3.2
cockpit-selinux-321-bp157.2.3.2
cockpit-storaged-321-bp157.2.3.2
cockpit-system-321-bp157.2.3.2
https://www.suse.com/security/cve/CVE-2026-4802.html
https://bugzilla.suse.com/1265040
Get the latest Linux and open source security news straight to your inbox.