VYPR

cockpit-files

by Red Hat

CVEs (3)

  • CVE-2026-91202MedSep 18, 2026
    risk 0.40cvss 6.1epss

    A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the…

  • CVE-2026-91205MedSep 18, 2026
    risk 0.39cvss 6.0epss

    A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the…

  • CVE-2026-91203MedSep 18, 2026
    risk 0.39cvss 6.0epss

    A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race,…