HIGH🇬🇧 English

CVE-2026-24893

CVSS 8.8v3.1pub. 2026-04-14upd. 2026-07-25

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. The vulnerability arises because user-controlled host attributes (specifically the host address) are expanded into monitoring command templates without validation, escaping, or quoting. These templates are later executed by the monitoring engine (Nagios/Icinga) via a shell, resulting in remote code execution. Version 5.5.2 patches the issue.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • It Novum Openitcockpit

    APP
    It-Novum
    < 5.5.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCECommand Injection
CWE
Referencje

Powiązane podatności

CVE-2020-10788CRITICAL9.1PL ✓ten sam produkt

openITCOCKPIT: Hardcodowany klucz API dla połączeń WebSocket

CVE-2020-10789CRITICAL9.8PL ✓ten sam produkt

Command Injection w terminalu webowym openITCOCKPIT przed wersją 3.7.3

CVE-2019-15490CRITICAL9.8PL ✓ten sam produkt

Command Injection w openITCOCKPIT umożliwiający zdalne wykonanie kodu

CVE-2019-15494CRITICAL9.8PL ✓ten sam produkt

SSRF w openITCOCKPIT umożliwiający nieautoryzowany dostęp do zasobów wewnętrznych

CVE-2026-24891HIGH7.5ten sam produkt

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and...