CVE-2026-38993
Cockpit is vulnerable to directory traversal
6.5
MEDIUM
CVSS 3.1
EPSS 0.12%
Description
Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.
How to fix CVE-2026-38993
To remediate CVE-2026-38993, upgrade the affected package to a fixed version below.
- —upgrade to 2.14.0 or later
Is CVE-2026-38993 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.14.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |