Junglewise Threat Intelligence

CVE-2026-24893: openITCOCKPIT command injection in host address macro expansion

CVE-2026-24893 · Severity: high · CVSS 8.8 · Published 2026-04-14

Executive brief

openITCOCKPIT is an open-source platform used by organizations to monitor the health and performance of their IT infrastructure. A security vulnerability in the host configuration module allows an authorized user to execute malicious commands on the underlying server. If exploited, an attacker could gain full control over the monitoring backend, potentially leading to data theft, service disruption, or a foothold to attack other systems within the corporate network.

Technical details

An OS command injection vulnerability exists in openITCOCKPIT Community Edition due to improper neutralization of special elements in the host address field. The application expands user-controlled host attributes, specifically the $HOSTADDRESS$ macro, into monitoring command templates (e.g., check_ping) without adequate validation or shell escaping. When the monitoring engine (Nagios/Icinga/Naemon) executes these templates via /bin/sh -c, shell metacharacters such as backticks or semicolons are interpreted, leading to remote code execution as the 'nagios' user. Exploitation requires network access to the web interface and valid credentials with permissions to add or modify hosts. The issue is addressed in version 5.5.2 by implementing a filter for dangerous characters in name and address fields.

Affected products

  • openITCOCKPIT openITCOCKPIT Community Edition < 5.5.2

Timeline

  • 2026-01-07: other: Vulnerability discovered by researcher h00die-gr3y
  • 2026-04-14: patched: Version 5.5.2 released
  • 2026-04-14: advisory: GitHub Security Advisory published

References