VDB
Sign up
CRITICAL9.8

PYSEC-2026-314

Cobbler vulnerable to arbitrary code execution

Quick fix

PYSEC-2026-314 — cobbler: upgrade to the fixed version with the command below.

pip install --upgrade 'cobbler>=3.0.0'

Details

Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cobbler
Introduced in: 0Fixed in: 3.0.0
Fixpip install --upgrade 'cobbler>=3.0.0'

References