← Vulnerability feed

Vulnerability record · CVE-2018-10931 · published 9 August 2018

CVE-2018-10931: Cobbler XMLRPC interface exposes privileged functions to unauthenticated users

Cobbler Project · Cobbler

Cobbler 2.6.x exposes all functions of its CobblerXMLRPCInterface class over XMLRPC, so the interface is reachable without authentication. A remote attacker can invoke privileged operations and upload files to arbitrary locations as the daemon, making this a full compromise of the Cobbler service.

9.8 CVSS 3.0 Critical EPSS 68% · top 0.7% CWE-749 · CWE-749
9.8CVSS 3.0 base score, v2 7.5
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS percentile, though no confirmed in-the-wild exploitation is recorded.

What it is

Cobbler 2.6.x exposes all functions of its CobblerXMLRPCInterface class over XMLRPC, so the interface is reachable without authentication. A remote attacker can invoke privileged operations and upload files to arbitrary locations as the daemon, making this a full compromise of the Cobbler service.

Impact

An unauthenticated attacker gains high privileges within Cobbler and can write files to arbitrary paths in the context of the Cobbler daemon, which can lead to code execution or full host compromise.

Attack surface

Reachable over the network via the XMLRPC endpoint; the CVSS vector shows no privileges and no user interaction required. Any host exposing the Cobbler XMLRPC service is directly exposed.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.68083 (99.29th percentile), indicating a high modeled likelihood of exploitation. References are advisories and issue tracking only, with no public exploit tag.

What to do

  • Apply the vendor fix from RHSA-2018:2372 or the corresponding Fedora package updates for Cobbler.
  • If patching is delayed, restrict network access to the Cobbler XMLRPC port to trusted management hosts only.
  • Disable or block the XMLRPC interface where it is not operationally required.
  • Run the Cobbler daemon with the least privilege possible and monitor its file-write paths.
  • Review the Red Hat Bugzilla entry for the documented mitigation guidance.

Detection

  • Monitor XMLRPC requests to the Cobbler endpoint for calls to privileged interface methods from unexpected sources.
  • Alert on new or modified files written by the Cobbler daemon outside expected directories.
  • Audit Cobbler daemon logs for unauthenticated or anomalous method invocations.
  • Baseline normal XMLRPC clients and flag first-seen source IPs hitting the Cobbler service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-10931 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed5.3CVE-2015-4902Oracle Java SE Deployment integrity check bypassCVE-2015-4902 is an unspecified vulnerability in the Deployment component of Oracle Java SE 6u101, 7u85, and 8u60. It allows remote attackers to affe…KEVEPSS 14%analysed9.8CVE-2024-7012Redhat satellite improper authentication vulnerabilityAn authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…EPSS 0.77%9.8CVE-2024-7923Redhat satellite improper authentication vulnerabilityAn authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…EPSS 0.81%9.8CVE-2021-40323Cobbler XMLRPC log poisoning leads to remote code executionCobbler before 3.3.0 allows log poisoning through an XMLRPC method that writes attacker-controlled input into the logfile, which is then processed as…EPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2018-10931), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.