CentOS 9 : cockpit-368-1.el9

high Nessus Plugin ID 363460

Synopsis

The remote CentOS host is missing one or more security updates for cockpit.

Description

The remote CentOS Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the cockpit-368-1.el9 build changelog.

- A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users. (CVE-2026-91149)

- Automatic update for cockpit-368-1.fc45. ##### **Changelog for cockpit** ``` * Wed Sep 23 2026 Packit <[email protected]> - 368-1 - Limit concurrent connections CVE-2026-91149 - Harden cockpit-ws against trailing slash CVE-2026-91147 - Sanitize URLs from PackageKit CVE-2026-91148 - Interactive file chooser for SSH keys - Bug fixes and translation updates - Resolves RHEL-263070, RHEL-262891, RHEL-253609 for rhel-10.4 - Resolves RHEL-263066 for rhel-9.10 ``` (CVE-2026-91148)

- A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.
(CVE-2026-91147)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the CentOS 9 Stream cockpit package.

See Also

https://kojihub.stream.centos.org/koji/buildinfo?buildID=131305

Plugin Details

Severity: High

ID: 363460

File Name: centos9_cockpit-368-1_131305.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.18

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-91149

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:centos:centos:9, p-cpe:/a:centos:centos:cockpit-bridge, p-cpe:/a:centos:centos:cockpit-doc, p-cpe:/a:centos:centos:cockpit-packagekit, p-cpe:/a:centos:centos:cockpit-storaged, p-cpe:/a:centos:centos:cockpit-system, p-cpe:/a:centos:centos:cockpit-ws-selinux, p-cpe:/a:centos:centos:cockpit-ws, p-cpe:/a:centos:centos:cockpit

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/CentOS/release, Host/CentOS/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/18/2026

Reference Information

CVE: CVE-2026-91147, CVE-2026-91148, CVE-2026-91149