OS Command Injection in openITCOCKPIT - CVE-2026-24893

 

OS Command Injection in openITCOCKPIT - CVE-2026-24893

Published: April 14, 2026


Vulnerability identifier: #VU125976
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24893
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in host configuration monitoring command generation when expanding user-supplied host address macros into shell-executed monitoring command templates. A remote user can submit a crafted host address to execute arbitrary code.

Exploitation requires permission to add or modify hosts, and both master and satellite monitoring setups are affected.


Affected software

openITCOCKPIT

How to mitigate CVE-2026-24893

Install security update from vendor's website.

openITCOCKPIT - update to 5.5.2

External References

Related Security Bulletins