CVE-2026-31891: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-31891 is a SQL Injection vulnerability in the MongoLite Aggregation Optimizer of Cockpit CMS, specifically via the toJsonExtractRaw() method in lib/MongoLite/Aggregation/Optimizer.php. It affects all Cockpit CMS versions prior to 2.13.5 (i.e., 2.13.4 and earlier) with API access enabled. The vulnerability was published on March 17, 2026, via a GitHub Security Advisory, with NVD publication on March 18, 2026. The GitHub Advisory Database assigns a CVSS v3.1 score of 7.7 (High) with Scope:Changed, while the NVD/Feedly data reflects a score of 6.5 (Medium) with Scope:Unchanged (GitHub Advisory, Cockpit Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), where field names supplied in aggregation queries to the /api/content/aggregate/{model} API endpoint are passed unsanitized to the toJsonExtractRaw() method in the MongoLite Aggregation Optimizer, which constructs raw SQLite SQL queries (GitHub Advisory). A similar sanitization fix had previously been applied to the toJsonPath() method in v2.13.3, but toJsonExtractRaw() was overlooked, leaving an injection vector open (Cockpit Advisory). An attacker with a valid read-only API key can craft a malicious aggregation pipeline with injected SQL in field names — for example, a payload like $title') as _id FROM collections_testcol-- — to manipulate the generated SQL query (PoC GitHub). This allows bypassing the _state=1 published-content filter and extracting arbitrary data from the underlying SQLite database (Red Hat Bugzilla).

Impact

Successful exploitation results in a high confidentiality impact: attackers can extract unauthorized data from the SQLite content database, including unpublished or restricted content that should not be publicly accessible (GitHub Advisory). Integrity and availability are not directly affected by this vulnerability. The scope of impact is limited to the content database of the affected Cockpit CMS instance, with no evidence of lateral movement capability or remote code execution (Cockpit Advisory).

Exploitability

A public proof-of-concept exploit is available on GitHub, providing a complete step-by-step guide with concrete payloads and curl commands targeting the /api/content/aggregate/{model} endpoint (PoC GitHub). The exploit requires only a valid read-only API key — the lowest privilege level — making it accessible to a broad range of potential attackers. As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.026% (0.013% per GitHub Advisory), indicating a currently low but non-zero probability of exploitation in the near term (GitHub Advisory). Tenable Nessus detection plugins (IDs 303008 and 303195) are available for scanning (Feedly).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Cockpit CMS instances running version 2.13.4 or earlier using search engines (Shodan, Censys) or web fingerprinting tools. Confirm API access is enabled by probing the /api/content/aggregate/{model} endpoint.
  2. Obtain API Key: Acquire a valid read-only API key — the minimum privilege required. This may be obtained through registration, social engineering, or prior credential exposure.
  3. Craft Malicious Aggregation Payload: Construct a JSON aggregation pipeline where a field name contains injected SQL. For example, use a payload such as $title') as _id FROM collections_testcol-- as a field name in the $project stage of the pipeline.
  4. Send Exploit Request: Submit the crafted pipeline via a URL-encoded curl command to the target endpoint:
curl -H 'api-key: <readonly_key>' 'https://target.example.com/api/content/aggregate/testcol?pipeline=<URL_ENCODED_PIPELINE_JSON>'
  1. Bypass Content Filter: The injected SQL manipulates the generated SQLite query to bypass the _state=1 filter, exposing unpublished or restricted content records.
  2. Extract Data: Parse the API response to retrieve unauthorized content from the SQLite database, including draft or restricted entries not intended for public access (PoC GitHub, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET/POST requests to /api/content/aggregate/{model} endpoints containing URL-encoded SQL metacharacters (e.g., ', --, FROM, SELECT) in pipeline parameters; requests from unexpected IP addresses using valid API keys.
  • Logs: Web server access logs showing requests to /api/content/aggregate/ with abnormally long or encoded pipeline query parameters; API responses returning content not matching the expected published (_state=1) dataset.
  • Application: API responses containing data from multiple collections or unexpected fields inconsistent with the requested model, suggesting SQL UNION or comment-based injection success.
  • File System: No direct file system artifacts expected, as the attack is query-based against the SQLite database; however, unexpected SQLite database read activity or database file access timestamps may be observable (PoC GitHub, GitHub Advisory).

Mitigation and workarounds

The vulnerability is patched in Cockpit CMS version 2.13.5, which applies field-name sanitization (identifier escaping and JSON path escaping) to the toJsonExtractRaw() method in lib/MongoLite/Aggregation/Optimizer.php — the same fix pattern used for toJsonPath() in v2.13.3 (Cockpit Release). All users on version 2.13.4 or earlier should upgrade to 2.13.5 or later immediately. If immediate patching is not possible, restrict network access to the /api/content/aggregate/{model} endpoint to trusted networks only, audit API key usage and access logs for suspicious aggregation queries, and consider revoking or rotating API keys that are not actively needed (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was discovered and credited to researcher ffasterss, who also published the public PoC on GitHub (GitHub Advisory). The advisory was published by Cockpit CMS maintainer aheinze on March 17, 2026. Social media activity was observed on Mastodon and Bluesky shortly after disclosure, with community discussion noting the low privilege bar (read-only API key) required for exploitation. Red Hat tracked the issue via Bugzilla as a high-severity vulnerability (Red Hat Bugzilla). Tenable released Nessus detection plugins within days of disclosure, reflecting prompt industry response (Feedly).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

bionic (esm-apps)

cockpit

Unknown

devel

cockpit

Unknown

focal (esm-apps)

cockpit

Unknown

jammy

cockpit

Unknown

jammy (esm-apps)

cockpit

Unknown

noble

cockpit

Unknown

noble (esm-apps)

cockpit

Unknown

resolute

cockpit

Unknown

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management