Security update for cockpit
This update for cockpit fixes the following issues - CVE-2026-0775: npm: loading of modules from an unsecured location can be used for local privilege escalation and arbitrary code execution in the context of a target user (bsc#1256521). - CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (bsc#1265040). - CVE-2026-29074: svgo: no guard against entity expansion or recursion when processing XML with custom entities can lead to DoS (bsc#1259290).
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for cockpit fixes the following issues - CVE-2026-0775: npm: loading of modules from an unsecured location can be used for local privilege escalation and arbitrary code execution in the context of a target user (bsc#1256521). - CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (bsc#1265040). - CVE-2026-29074: svgo: no guard against entity expansion or recursion when processing XML with custom entities can lead to DoS (bsc#1259290).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1256521
- https://bugzilla.suse.com/1259290
- https://bugzilla.suse.com/1265040
- https://www.suse.com/security/cve/CVE-2026-0775
- https://www.suse.com/security/cve/CVE-2026-29074
- https://www.suse.com/security/cve/CVE-2026-4802
- https://www.suse.com/support/update/announcement/2026/suse-su-20262019-1/