← Vulnerability feed

Vulnerability record · CVE-2020-35131 · published 8 January 2021

CVE-2020-35131: Cockpit PHP code injection in MongoLite Database leads to RCE

Agentejo · Cockpit

Cockpit before 0.6.1 passes attacker-controlled JSON values into registerCriteriaFunction in lib/MongoLite/Database.php, allowing injection of custom PHP code. Because the injected code executes on the server, this is a full remote command execution flaw in an unauthenticated web-reachable component.

9.8 CVSS 3.1 Critical EPSS 51% · top 1.1% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable PHP code injection with a public exploit and very high EPSS score warrants immediate patching.

What it is

Cockpit before 0.6.1 passes attacker-controlled JSON values into registerCriteriaFunction in lib/MongoLite/Database.php, allowing injection of custom PHP code. Because the injected code executes on the server, this is a full remote command execution flaw in an unauthenticated web-reachable component.

Impact

An attacker can execute arbitrary PHP and operating system commands on the Cockpit host, leading to full server compromise and access to data and credentials handled by the application.

Attack surface

Reachable over the network through the /auth/check or /auth/requestreset URIs by supplying crafted JSON data; the CVSS vector indicates no privileges or user interaction are required.

Exploitation

A public Exploit-DB entry (49390) exists, and EPSS is 0.51299 (98.9th percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.

What to do

  • Upgrade Cockpit to 0.6.1 or later, which contains the fix in lib/MongoLite/Database.php.
  • If immediate upgrade is not possible, restrict network access to /auth/check and /auth/requestreset and to the Cockpit instance generally.
  • Review and harden any custom code paths that pass user-supplied JSON into MongoLite query criteria functions.
  • Run the Cockpit service with least privilege and in a segregated environment to limit post-exploitation reach.

Detection

  • Inspect web logs for POST requests to /auth/check or /auth/requestreset containing PHP code or unusual JSON structures.
  • Monitor for unexpected PHP process execution or child processes spawned by the web server.
  • Look for newly written or modified PHP files under the Cockpit webroot that were not part of a deployment.
  • Alert on outbound network connections from the Cockpit host that are inconsistent with normal application behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35131 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4825Agentejo cockpit unrestricted file upload vulnerabilityA vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque…EPSS 0.72%9.8CVE-2022-2713Agentejo cockpit insufficient session expiration vulnerabilityInsufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.EPSS 1.2%9.8CVE-2020-35846Agentejo Cockpit NoSQL injection in Auth check functionCockpit before 0.11.2 is vulnerable to NoSQL injection through the check function in Controller/Auth.php. The flaw is reachable over the network with…EPSS 93%analysed9.8CVE-2020-35847Agentejo Cockpit NoSQL injection in password resetCockpit before 0.11.2 passes unsanitized input into the resetpassword function in Controller/Auth.php, allowing NoSQL injection. The flaw is remotely…EPSS 98%analysed9.8CVE-2020-35848Agentejo Cockpit NoSQL injection in newpassword functionCockpit before 0.11.2 is vulnerable to NoSQL injection through the Controller/Auth.php newpassword function. The flaw lets an unauthenticated remote …EPSS 75%analysed9.8CVE-2018-15540Agentejo cockpit path traversal vulnerabilityAgentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended …EPSS 2.3%9.1CVE-2017-14611Agentejo cockpit server-side request forgery (ssrf) vulnerabilitySSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur…EPSS 1.9%8.8CVE-2023-4195Agentejo cockpit php remote file inclusion vulnerabilityPHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-35131), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.