medium · CVSS v3 6.1
CVE-2026-91202
CVE-2026-91202 is a local privilege escalation flaw in cockpit-files that allows a low‑privileged user to change file ownership via a crafte
Overview
CVE-2026-91202 is a local privilege escalation flaw in cockpit-files that allows a low‑privileged user to change file ownership via a crafted symlink during the Paste as owner operation. The vulnerability can compromise data integrity and potentially leak confidential data if ownership is granted to unauthorized users. It requires user interaction to select a non‑original owner.
Description
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
Impact
The flaw violates Integrity by allowing arbitrary ownership changes, potentially leading to unauthorized modification or deletion of files. Confidentiality may be affected if the new owner gains read access to sensitive data. The primary impact is on systems running the cockpit web interface, especially those with local users who can access the Paste as owner feature.
Remediation
Apply the latest cockpit update that removes the Paste as owner privilege for non‑root users or patches the symlink handling. Disable the Paste as owner function via cockpit configuration or set file permissions to restrict symlink creation. Monitor for unexpected ownership changes and audit file ownership regularly.
Risk context
Severity is medium (CVSS 6.1). No EPSS data available. The risk is moderate; defenders should prioritize patching within the next maintenance window.
Affected products
- cockpit-files
- Red Hat Enterprise Linux cockpit
- Fedora cockpit
- CentOS cockpit
- Ubuntu cockpit
Scores
- Severity
- medium
- CVSS v2
- 5.7
- CVSS v3
- 6.1
- CVSS v4
- —
- EPSS
- —