Vulnerability record · CVE-2020-35846 · published 30 December 2020
CVE-2020-35846: Agentejo Cockpit NoSQL injection in Auth check function
Agentejo · Cockpit
Cockpit before 0.11.2 is vulnerable to NoSQL injection through the check function in Controller/Auth.php. The flaw is reachable over the network without authentication, and public exploit material describes chaining it to remote command execution, making it a serious risk for exposed Cockpit instances.
Description
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable NoSQL injection with a public exploit chain to remote command execution and very high EPSS probability.
What it is
Cockpit before 0.11.2 is vulnerable to NoSQL injection through the check function in Controller/Auth.php. The flaw is reachable over the network without authentication, and public exploit material describes chaining it to remote command execution, making it a serious risk for exposed Cockpit instances.
Impact
An unauthenticated attacker can inject into the authentication query, potentially bypassing login and, per the public exploit write-up, escalating to remote command execution on the host.
Attack surface
Reached over the network via HTTP against the Cockpit authentication endpoint; the CVSS vector indicates no privileges and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.93292, 99.8th percentile) and a public Packet Storm exploit titled for NoSQL injection to remote command execution exists, indicating active interest and available exploit code.
What to do
- Upgrade Cockpit to 0.11.2 or later, applying the vendor commits referenced in the advisory.
- If immediate upgrade is not possible, restrict network access to the Cockpit login and admin endpoints to trusted sources.
- Validate and sanitize authentication input so query operators cannot be injected into the NoSQL lookup.
- Review logs and accounts for signs of unauthorized access or post-exploitation activity before and after patching.
Detection
- Monitor HTTP requests to Cockpit authentication endpoints for NoSQL operator patterns such as $ne, $gt, $regex or nested JSON objects in credentials fields.
- Alert on unexpected outbound connections or process creation from the Cockpit web server process, which may indicate command execution.
- Audit Cockpit access logs for successful logins from unusual source IPs or with malformed credential payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-35846 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35846), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.