What is CVE-2026-73680?
This vulnerability affects Cockpit CMS versions 2.14.0 and earlier, allowing command injection through the FFmpeg integration. An authenticated user with only assets/upload permission can execute arbitrary commands on the server by uploading a video file with a filename containing shell metacharacters. Systems should be updated immediately or file names in FFmpeg calls must be strictly sanitized.
Azərbaycanca: Bu zəiflik Cockpit CMS-in 2.14.0 və əvvəlki versiyalarında FFmpeg inteqrasiyasında əmr inyeksiyasına imkan verir. Yalnız assets/upload icazəsi olan autentifikasiyalı istifadəçi, fayl adında shell metacharakterləri olan video yükləyərək serverdə ixtiyari əmrlər icra edə bilər. Təsirə məruz qalmamaq üçün dərhal ən son versiyaya yenilənməli və ya FFmpeg çağırışlarında fayl adlarının ciddi sanitizasiyası təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of Cockpit CMS are vulnerable to CVE-2026-73680?
Cockpit CMS versions 2.14.0 and earlier are affected by this vulnerability.
What permissions does an attacker need to exploit CVE-2026-73680?
An attacker only needs to be an authenticated user with assets/upload permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.