CVE-2026-24893: It-Novum Openitcockpit
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. The vulnerability arises because user-controlled host attributes (specifically the host address) are expanded into monitoring command templates without validation, escaping, or quoting. These templates are later executed by the monitoring engine (Nagios/Icinga) via a shell, resulting in remote code execution. Version 5.5.2 patches the issue.
Affected products
- It-Novum Openitcockpit: before 5.5.2 (fixed in 5.5.2)
Published 2026-04-14. Last modified 2026-07-25.