Vulnerability record · CVE-2018-10931 · published 9 August 2018
CVE-2018-10931: Cobbler XMLRPC interface exposes privileged functions to unauthenticated users
Cobbler Project · Cobbler
Cobbler 2.6.x exposes all functions of its CobblerXMLRPCInterface class over XMLRPC, so the interface is reachable without authentication. A remote attacker can invoke privileged operations and upload files to arbitrary locations as the daemon, making this a full compromise of the Cobbler service.
Description
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS percentile, though no confirmed in-the-wild exploitation is recorded.
What it is
Cobbler 2.6.x exposes all functions of its CobblerXMLRPCInterface class over XMLRPC, so the interface is reachable without authentication. A remote attacker can invoke privileged operations and upload files to arbitrary locations as the daemon, making this a full compromise of the Cobbler service.
Impact
An unauthenticated attacker gains high privileges within Cobbler and can write files to arbitrary paths in the context of the Cobbler daemon, which can lead to code execution or full host compromise.
Attack surface
Reachable over the network via the XMLRPC endpoint; the CVSS vector shows no privileges and no user interaction required. Any host exposing the Cobbler XMLRPC service is directly exposed.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.68083 (99.29th percentile), indicating a high modeled likelihood of exploitation. References are advisories and issue tracking only, with no public exploit tag.
What to do
- Apply the vendor fix from RHSA-2018:2372 or the corresponding Fedora package updates for Cobbler.
- If patching is delayed, restrict network access to the Cobbler XMLRPC port to trusted management hosts only.
- Disable or block the XMLRPC interface where it is not operationally required.
- Run the Cobbler daemon with the least privilege possible and monitor its file-write paths.
- Review the Red Hat Bugzilla entry for the documented mitigation guidance.
Detection
- Monitor XMLRPC requests to the Cobbler endpoint for calls to privileged interface methods from unexpected sources.
- Alert on new or modified files written by the Cobbler daemon outside expected directories.
- Audit Cobbler daemon logs for unauthenticated or anomalous method invocations.
- Baseline normal XMLRPC clients and flag first-seen source IPs hitting the Cobbler service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-10931 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10931), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.