Vulnerability record · CVE-2020-35847 · published 30 December 2020
CVE-2020-35847: Agentejo Cockpit NoSQL injection in password reset
Agentejo · Cockpit
Cockpit before 0.11.2 passes unsanitized input into the resetpassword function in Controller/Auth.php, allowing NoSQL injection. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so any exposed Cockpit instance is at risk.
Description
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote NoSQL injection with a 9.8 CVSS score, public exploit code and near-maximum EPSS probability makes this an urgent patch target.
What it is
Cockpit before 0.11.2 passes unsanitized input into the resetpassword function in Controller/Auth.php, allowing NoSQL injection. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so any exposed Cockpit instance is at risk.
Impact
An attacker can manipulate the password reset query, potentially bypassing authentication and gaining full control of the application and its data. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the password reset endpoint in Controller/Auth.php; the CVSS vector shows no privileges and no user interaction required. No authentication is needed to send the malicious request.
Exploitation
Public exploit code is referenced on Packet Storm, and EPSS is 0.98165 (99.9th percentile), indicating very high likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Upgrade Cockpit to 0.11.2 or later, applying the vendor commits referenced in the advisory.
- If immediate upgrade is not possible, restrict network access to the Cockpit password reset endpoint and admin interface.
- Validate and sanitize all input reaching the resetpassword function, rejecting non-string or unexpected types.
- Monitor Cockpit logs for anomalous password reset requests and unexpected authentication changes.
Detection
- Alert on password reset requests containing NoSQL operators such as $ne, $gt, $regex or $where in parameters.
- Baseline normal reset request volume and flag spikes or requests from unusual source IPs.
- Review Cockpit application logs for successful logins or password changes that follow reset requests from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-35847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.