#VU125976 OS Command Injection in openITCOCKPIT - CVE-2026-24893
Published: April 14, 2026
openITCOCKPIT
it-novum GmbH
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to command injection in host configuration monitoring command generation when expanding user-supplied host address macros into shell-executed monitoring command templates. A remote user can submit a crafted host address to execute arbitrary code.
Exploitation requires permission to add or modify hosts, and both master and satellite monitoring setups are affected.