CRITICAL9.8
PYSEC-2026-314
Cobbler vulnerable to arbitrary code execution
Quick fix
PYSEC-2026-314 — cobbler: upgrade to the fixed version with the command below.
pip install --upgrade 'cobbler>=3.0.0'Details
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000469[ADVISORY]
- https://github.com/cobbler/cobbler/issues/1845[WEB]
- https://github.com/cobbler/cobbler/commit/4b20397425a5d42a2d8927233654f4d7435bd4c2[WEB]
- https://github.com/cobbler/cobbler[PACKAGE]
- https://pypi.org/project/cobbler[PACKAGE]
- https://github.com/advisories/GHSA-96hw-v598-jvgh[ADVISORY]