CVE-2026-57856
Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', $bucket), which permits '..' and '../' sequences. The sanitized value is interpolated into a Flysystem path as uploads://buckets/{bucket}. Flysystem's WhitespacePathNormalizer resolves 'buckets/..' to the empty string (the uploads storage root) without raising PathTraversalDetected because the '..' has a preceding component to consume. An authenticated low-privileged user can send a crafted request with a '../' bucket name to list, upload, and delete files across all buckets, including those belonging to other users or roles
- Affected products
- Cockpit Cms, Cockpit
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.4% (32th percentile)
- Weakness
- CWE-22
- NVD status
- Deferred
- Published
- 2026-07-13
No indexed exploits for CVE-2026-57856 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-57856 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.