CVE-2026-39275

Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components

  • Published Aug 26, 2026
  • CVSS 6.1 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-39275 at the National Vulnerability Database