Vulnerability Description
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sanitizer runs, enabling injected shell metacharacters such as backticks, $(), and semicolons to escape the FFmpeg command context and execute as the web-server user.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Cockpit-HQ/Cockpit
- https://github.com/Cockpit-HQ/Cockpit/commit/28813596f57685f63d3a48f655e8e9bd2b5
- https://link.mateocallec.com/MFC-2026-002
- https://www.vulncheck.com/advisories/cockpit-cms-authenticated-command-injection
FAQ
What is CVE-2026-73680?
CVE-2026-73680 is a vulnerability with a CVSS score of 8.8 (HIGH). Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands b...
How severe is CVE-2026-73680?
CVE-2026-73680 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73680?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.