← Vulnerability feed

Vulnerability record · CVE-2021-40324 · published 4 October 2021

CVE-2021-40324: Cobbler upload_log_data arbitrary file write

Cobbler Project · Cobbler

Cobbler before 3.3.0 allows arbitrary file write operations through the upload_log_data function. Because the flaw is an unrestricted file upload (CWE-434) reachable over the network without credentials, an attacker can place files anywhere the Cobbler service can write, which matters for any exposed provisioning server.

7.5 CVSS 3.1 High EPSS 69% · top 0.7% CWE-434 · Unrestricted file upload
7.5CVSS 3.1 base score, v2 5.0
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file write with a 7.5 CVSS score and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

Cobbler before 3.3.0 allows arbitrary file write operations through the upload_log_data function. Because the flaw is an unrestricted file upload (CWE-434) reachable over the network without credentials, an attacker can place files anywhere the Cobbler service can write, which matters for any exposed provisioning server.

Impact

An attacker gains the ability to write arbitrary files on the Cobbler host, which can lead to code execution or service takeover depending on where files land. Integrity is rated High; confidentiality and availability are not affected per the CVSS vector.

Attack surface

Reached over the network via the upload_log_data interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not detail which endpoint or port, so defenders should treat any network-reachable Cobbler instance as exposed.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.68635 (99.3rd percentile), indicating a high modeled likelihood of exploitation activity. References are limited to the patch commit and the 3.3.0 release, with no public exploit or PoC tags supplied.

What to do

  • Upgrade Cobbler to 3.3.0 or later, which contains the fix commit d8f60bbf14a838c8c8a1dba98086b223e35fe70a.
  • Restrict network access to the Cobbler service and its XML-RPC/API endpoints to trusted management networks only.
  • Run the Cobbler service with a least-privilege account and confine its writable directories to the minimum required paths.
  • Monitor and alert on unexpected file creation or modification in Cobbler-managed directories and web-accessible paths.
  • If patching is delayed, disable or block the upload_log_data functionality where it is not operationally required.

Detection

  • Audit Cobbler logs and web server access logs for calls to upload_log_data, especially from unexpected source addresses.
  • Monitor file integrity in Cobbler data, tftpboot, and web root directories for new or modified files outside normal provisioning activity.
  • Alert on new executable or script files appearing in paths writable by the Cobbler service account.
  • Baseline normal Cobbler API clients and flag upload_log_data requests from hosts that have not previously used the service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40324 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40323Cobbler XMLRPC log poisoning leads to remote code executionCobbler before 3.3.0 allows log poisoning through an XMLRPC method that writes attacker-controlled input into the logfile, which is then processed as…EPSS 87%analysed9.8CVE-2018-10931Cobbler XMLRPC interface exposes privileged functions to unauthenticated usersCobbler 2.6.x exposes all functions of its CobblerXMLRPCInterface class over XMLRPC, so the interface is reachable without authentication. A remote a…EPSS 68%analysed9.8CVE-2017-1000469Cobbler project cobbler improper input validation vulnerabilityCobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as r…EPSS 5.6%9.1CVE-2022-0860Cobbler project cobbler improper authorization vulnerabilityImproper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.EPSS 2.3%7.8CVE-2021-45082Cobbler project cobbler command injection vulnerabilityAn issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Pyth…EPSS 0.50%7.5CVE-2021-40325Cobbler project cobbler vulnerabilityCobbler before 3.3.0 allows authorization bypass for modification of settings.EPSS 1.4%7.1CVE-2021-45083Cobbler project cobbler incorrect default permissions vulnerabilityAn issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that…EPSS 0.31%6.8CVE-2011-4953Cobbler project cobbler improper input validation vulnerabilityThe set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2021-40324), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.