VDB
Sign up
—

PYSEC-2026-792

Cobbler subject to Command Injection

Quick fix

PYSEC-2026-792 — cobbler: upgrade to the fixed version with the command below.

pip install --upgrade 'cobbler>=2.6.0'

Details

A Command Injection in action_power.py in Cobbler prior to v2.6.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cobbler
Introduced in: 0Fixed in: 2.6.0
Fixpip install --upgrade 'cobbler>=2.6.0'

References