VDB
Sign up
—

PYSEC-2026-795

Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability

Quick fix

PYSEC-2026-795 — cobbler: upgrade to the fixed version with the command below.

pip install --upgrade 'cobbler>=1.2.9'

Details

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code with the root privileges in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cobbler
Introduced in: 0Fixed in: 1.2.9
Fixpip install --upgrade 'cobbler>=1.2.9'

References