VYPR

cockpit-machines

by Red Hat

CVEs (3)

  • CVE-2026-92768MedSep 18, 2026
    risk 0.36cvss 5.5epss

    A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component…

  • CVE-2026-92747MedSep 18, 2026
    risk 0.33cvss 5.0epss

    A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py`…

  • CVE-2026-92745MedSep 18, 2026
    risk 0.33cvss 5.0epss

    A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a…