CVE-2026-105217 - Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php
CVE ID :CVE-2026-105217
Published : Oct. 4, 2026, 6:16 p.m. | 57 minutes ago
Description :Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 4, 2026, 6:16 p.m. | 57 minutes ago
Description :Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...