← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 4, 2026 · 18:16via CVEFeed

CVE-2026-105217 - Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php

Brief

CVE ID : CVE-2026-105217

Published : Oct. 4, 2026, 6:16 p. m.

  • 1 hour, 15 minutes ago

Description : Cockpit CMS 2.

  • 0 before 2.
  • 1 disables TLS certificate verification in the cron. php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.

Severity: 3.1

  • LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→