CVE-2026-31891 | Cockpit-HQ Cockpit up to 2.13.4 Aggregation Query Optimizer.php toJsonPath sql injection (GHSA-7x5c-vfhj-9628 / Nessus ID 303008)
A vulnerability was found in Cockpit-HQ Cockpit up to 2.13.4. It has been classified as critical. Affected by this vulnerability is the function toJsonPath in the library lib/MongoLite/Aggregation/Optimizer.php of the component Aggregation Query Handler. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-31891. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.