CVE-2026-24893 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 14, 2026
openITCOCKPIT - Command Injection
Published: April 14, 2026Updated: April 14, 2026Remote Exploitable
Overview
openITCOCKPIT Community Edition < 5.5.2 contains a command injection caused by unvalidated expansion of user-controlled host attributes in monitoring command templates, letting authenticated users with host modification permissions execute arbitrary OS commands.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated users with host modification permissions can execute arbitrary OS commands on the monitoring backend, leading to full system compromise.
Mitigation
Upgrade to version 5.5.2 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-24893
- Severity
- High
- CVSS Score
- 8.8
- Type
- command_injection
- Status
- new
CWE
- CWE-20
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H