← Vulnerability feed

Vulnerability record · CVE-2020-35847 · published 30 December 2020

CVE-2020-35847: Agentejo Cockpit NoSQL injection in password reset

Agentejo · Cockpit

Cockpit before 0.11.2 passes unsanitized input into the resetpassword function in Controller/Auth.php, allowing NoSQL injection. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so any exposed Cockpit instance is at risk.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote NoSQL injection with a 9.8 CVSS score, public exploit code and near-maximum EPSS probability makes this an urgent patch target.

What it is

Cockpit before 0.11.2 passes unsanitized input into the resetpassword function in Controller/Auth.php, allowing NoSQL injection. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so any exposed Cockpit instance is at risk.

Impact

An attacker can manipulate the password reset query, potentially bypassing authentication and gaining full control of the application and its data. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the password reset endpoint in Controller/Auth.php; the CVSS vector shows no privileges and no user interaction required. No authentication is needed to send the malicious request.

Exploitation

Public exploit code is referenced on Packet Storm, and EPSS is 0.98165 (99.9th percentile), indicating very high likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.

What to do

  • Upgrade Cockpit to 0.11.2 or later, applying the vendor commits referenced in the advisory.
  • If immediate upgrade is not possible, restrict network access to the Cockpit password reset endpoint and admin interface.
  • Validate and sanitize all input reaching the resetpassword function, rejecting non-string or unexpected types.
  • Monitor Cockpit logs for anomalous password reset requests and unexpected authentication changes.

Detection

  • Alert on password reset requests containing NoSQL operators such as $ne, $gt, $regex or $where in parameters.
  • Baseline normal reset request volume and flag spikes or requests from unusual source IPs.
  • Review Cockpit application logs for successful logins or password changes that follow reset requests from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4825Agentejo cockpit unrestricted file upload vulnerabilityA vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque…EPSS 0.72%9.8CVE-2022-2713Agentejo cockpit insufficient session expiration vulnerabilityInsufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.EPSS 1.2%9.8CVE-2020-35131Cockpit PHP code injection in MongoLite Database leads to RCECockpit before 0.6.1 passes attacker-controlled JSON values into registerCriteriaFunction in lib/MongoLite/Database.php, allowing injection of custom…EPSS 51%analysed9.8CVE-2020-35846Agentejo Cockpit NoSQL injection in Auth check functionCockpit before 0.11.2 is vulnerable to NoSQL injection through the check function in Controller/Auth.php. The flaw is reachable over the network with…EPSS 93%analysed9.8CVE-2020-35848Agentejo Cockpit NoSQL injection in newpassword functionCockpit before 0.11.2 is vulnerable to NoSQL injection through the Controller/Auth.php newpassword function. The flaw lets an unauthenticated remote …EPSS 75%analysed9.8CVE-2018-15540Agentejo cockpit path traversal vulnerabilityAgentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended …EPSS 2.3%9.1CVE-2017-14611Agentejo cockpit server-side request forgery (ssrf) vulnerabilitySSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur…EPSS 1.9%8.8CVE-2023-4195Agentejo cockpit php remote file inclusion vulnerabilityPHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-35847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.