Back to overview

CVE-2026-13533

MEDIUM
5.3
CVSS 3.1
Description
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Configuration settings should be changed. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-13533
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 09:22 UTC
Published
2026-06-29 04:00 UTC
Last updated
2026-06-29 04:00 UTC
Primary CWE
CWE-552
Files or Directories Accessible
Vendor / Product
agentejo / Cockpit CMS
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R
Affected products (1)
VendorProductPlatformVersions
agentejo Cockpit CMS 0.12.0, 0.12.1, 0.12.2
Weakness (CWE)
CWESourceDescription
CWE-425 cna Direct Request
CWE-552 cna Files or Directories Accessible
CVSS scores (4)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R
5.3 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R
5.0 N/D 2.0 cna AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR
References (5)
Back to overview