Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24893

32
FAUCET Score

openITCOCKPIT Community Edition versions prior to 5.5.2 contains a command injection vulnerability in host attribute handling that allows authenticated users with host management permissions to execute arbitrary operating system commands on the monitoring backend. The flaw occurs because user-supplied host address data is unsanitized when inserted into monitoring command templates executed by Nagios or Icinga through shell processes, enabling remote code execution. The vulnerability carries a HIGH severity rating with a CVSS score of 8.8. It requires network access and low attack complexity, but necessitates valid user credentials with host modification privileges. Successful exploitation results in complete system compromise, including confidentiality, integrity, and availability impacts to the monitoring infrastructure. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and has not been observed in active exploitation. The EPSS score of 0.0038 indicates this is a lower-priority threat relative to the broader vulnerability landscape. Community attention appears limited, suggesting slow adoption or disclosure. Organizations running openITCOCKPIT Community Edition should prioritize upgrading to version 5.5.2 to remediate this authentication-dependent but high-impact risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.5.2CPE matchmatch criteria
cpe:2.3:a:it-novum:openitcockpit:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.40%
Probability of exploitation in next 30 days
EPSS Percentile
69.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0140 is in the 67th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / openITCOCKPIT/openITCOCKPIT/releases/tag/openITCOCKPIT-5.5.2
ProductRelease Notes
github.com / openITCOCKPIT/openITCOCKPIT/security/advisories/GHSA-789q-pw85-j2q2
MitigationVendor Advisory
openitcockpit.io / blog/posts/2026/2026-04-14-openitcockpit-agent-3.6.0-and-5.5.2
Press/Media CoverageRelease Notes