Back

CVE-2018-1000226

CRITICAL

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

Published: Aug 20, 2018 Modified: Jun 17, 2026
CWE-732

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
cobblerd cobbler * ≥ 2.0.0

GitHub Security Advisory GHSA-f88q-22g8-frcg

Cobbler Improper Validation of Security Tokens

pip cobbler <= 2.6.11 Fixed: 3.0.0

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 12.48%

Top 4% most likely to be exploited

Threat Score 42.9 / 100

Data Sources

NVD EPSS GitHub