OS Command Injection in openITCOCKPIT - CVE-2026-24893

 

OS Command Injection in openITCOCKPIT - CVE-2026-24893

Published: April 14, 2026


Vulnerability identifier: #VU125976
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-24893
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: it-novum GmbH
Affected software:
openITCOCKPIT

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in host configuration monitoring command generation when expanding user-supplied host address macros into shell-executed monitoring command templates. A remote user can submit a crafted host address to execute arbitrary code.

Exploitation requires permission to add or modify hosts, and both master and satellite monitoring setups are affected.


How to mitigate CVE-2026-24893

Install security update from vendor's website.

Sources