LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-24893

CVE-2026-24893 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 14, 2026

openITCOCKPIT - Command Injection

Published: April 14, 2026Updated: April 14, 2026Remote Exploitable

Overview

openITCOCKPIT Community Edition < 5.5.2 contains a command injection caused by unvalidated expansion of user-controlled host attributes in monitoring command templates, letting authenticated users with host modification permissions execute arbitrary OS commands.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Authenticated users with host modification permissions can execute arbitrary OS commands on the monitoring backend, leading to full system compromise.

Mitigation

Upgrade to version 5.5.2 or later.

Details

CVE ID
CVE-2026-24893
Severity
High
CVSS Score
8.8
Type
command_injection
Status
new

CWE

  • CWE-20

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H