Sploitus

CVE-2026-57856

No indexed exploits for CVE-2026-57856 yet

Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', $bucket), which permits '..' and '../' sequences. The sanitized value is interpolated into a Flysystem path as uploads://buckets/{bucket}. Flysystem's WhitespacePathNormalizer resolves 'buckets/..' to the empty string (the uploads storage root) without raising PathTraversalDetected because the '..' has a preceding component to consume. An authenticated low-privileged user can send a crafted request with a '../' bucket name to list, upload, and delete files across all buckets, including those belonging to other users or roles

Affected products
Cockpit Cms, Cockpit
CVSS 3.1
8.8 HIGH
EPSS
0.4% (32th percentile)
Weakness
CWE-22
NVD status
Deferred
Published
2026-07-13
CVE-2026-57856 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-57856 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-57856 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.