VDB
Sign up
—

PYSEC-2026-797

Cobbler Path Traversal vulnerability

Quick fix

PYSEC-2026-797 — cobbler: upgrade to the fixed version with the command below.

pip install --upgrade 'cobbler>=2.4.7'

Details

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cobbler
Introduced in: 2.4.0Fixed in: 2.4.7
Fixpip install --upgrade 'cobbler>=2.4.7'

References