#VU125976 OS Command Injection in openITCOCKPIT - CVE-2026-24893

 

#VU125976 OS Command Injection in openITCOCKPIT - CVE-2026-24893

Published: April 14, 2026


Vulnerability identifier: #VU125976
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-24893
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
openITCOCKPIT
Software vendor:
it-novum GmbH

Description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in host configuration monitoring command generation when expanding user-supplied host address macros into shell-executed monitoring command templates. A remote user can submit a crafted host address to execute arbitrary code.

Exploitation requires permission to add or modify hosts, and both master and satellite monitoring setups are affected.


Remediation

Install security update from vendor's website.

External links