CVE-2026-92747

MEDIUM CVSS 3.1: 5.0 EPSS 0.14%
Updated Sep 19, 2026
Parameter Value
CVSS 5.0 (MEDIUM)
Type CWE-214
Public PoC No

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation.

The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)