CVE-2018-1000226 is a critical Incorrect Access Control vulnerability in the XMLRPC API of Cobbler versions 2.6.11+ (and potentially older), affecting both cobblerd and cobbler. This flaw allows unauthenticated attackers to bypass security token validation, leading to privilege escalation, data manipulation or exfiltration, and LDAP credential harvesting. With a CVSS score of 9.8 (Critical), it is easily exploitable over the network without user interaction. While not listed in KEV or having active social media discussion, a Nuclei template exists for an authentication bypass, indicating public exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0CPE matchmatch criteria | cpe:2.3:a:cobblerd:cobbler:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.