Vulnerability Description
Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', $bucket), which permits '..' and '../' sequences. The sanitized value is interpolated into a Flysystem path as uploads://buckets/{bucket}. Flysystem's WhitespacePathNormalizer resolves 'buckets/..' to the empty string (the uploads storage root) without raising PathTraversalDetected because the '..' has a preceding component to consume. An authenticated low-privileged user can send a crafted request with a '../' bucket name to list, upload, and delete files across all buckets, including those belonging to other users or roles
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/sermikr0/821c4edd3c34e98a62a50b07707785bd
- https://github.com/Cockpit-HQ/Cockpit/commit/dde2d1d74f5f4e11de42a298918ea8c9684
- https://github.com/cockpit-hq/cockpit
- https://www.vulncheck.com/advisories/cockpit-cms-missing-authorization-in-bucket
- https://www.vulncheck.com/advisories/cockpit-cms-path-traversal-via-bucket-name-
- https://gist.github.com/sermikr0/821c4edd3c34e98a62a50b07707785bd
FAQ
What is CVE-2026-57856?
CVE-2026-57856 is a vulnerability with a CVSS score of 8.8 (HIGH). Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_...
How severe is CVE-2026-57856?
CVE-2026-57856 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57856?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.