Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openitcockpit
Openitcockpit openitcockpit |
|
| Vendors & Products |
Openitcockpit
Openitcockpit openitcockpit |
Wed, 15 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. The vulnerability arises because user-controlled host attributes (specifically the host address) are expanded into monitoring command templates without validation, escaping, or quoting. These templates are later executed by the monitoring engine (Nagios/Icinga) via a shell, resulting in remote code execution. Version 5.5.2 patches the issue. | |
| Title | openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion | |
| Weaknesses | CWE-20 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-15T13:40:30.971Z
Reserved: 2026-01-27T19:35:20.529Z
Link: CVE-2026-24893
Updated: 2026-04-15T13:40:27.440Z
Status : Received
Published: 2026-04-14T21:16:24.987
Modified: 2026-04-14T21:16:24.987
Link: CVE-2026-24893
No data.
OpenCVE Enrichment
Updated: 2026-04-15T14:41:09Z