CVE-2026-24892
CVE-2026-24892 is a high-severity vulnerability in It-novum Openitcockpit with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-502.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (56th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-7793
- Weakness: CWE-502
- Affected product: It-novum Openitcockpit
- Published:
- Last modified:
Description
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced application state is unserialized without restricting allowed classes. Although no current application endpoint was found to introduce PHP objects into this data path, the presence of an unrestricted unserialize() call constitutes a latent PHP object injection vulnerability. If future code changes, plugins, or refactors introduce object values into this path, the vulnerability could become immediately exploitable with severe impact, including potential remote code execution.
Frequently asked questions
- What is CVE-2026-24892?
- openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced application state is unserialized without restricting allowed classes. Although no current application endpoint was found to introduce PHP objects into this data path, the presence of an unrestricted unserialize() call constitutes a latent PHP object injection vulnerability. If future code changes, plugins, or refactors introduce object values into this path, the vulnerability could become immediately exploitable with severe impact, including potential remote code execution.
- How severe is CVE-2026-24892?
- CVE-2026-24892 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-24892 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (56th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-24892?
- CVE-2026-24892 affects It-novum Openitcockpit. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-24892?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-24892 have an EU (EUVD) identifier?
- Yes. CVE-2026-24892 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-7793.
- When was CVE-2026-24892 published?
- CVE-2026-24892 was published on 2026-02-20 and last updated on 2026-06-17.
References
- https://github.com/openITCOCKPIT/openITCOCKPIT/commit/975e0d0dfb79898568afbbfdba8f647d92612a69
- https://github.com/openITCOCKPIT/openITCOCKPIT/releases/tag/openITCOCKPIT-5.4.0
- https://github.com/openITCOCKPIT/openITCOCKPIT/security/advisories/GHSA-g83p-vvjm-g39x
Affected products (1)
- cpe:2.3:a:it-novum:openitcockpit:*:*:*:*:*:*:*:*
More vulnerabilities in It-novum Openitcockpit
- CVE-2020-10789 — Critical (CVSS 9.8): openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell…
- CVE-2019-15494 — Critical (CVSS 9.8): openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
- CVE-2019-15490 — Critical (CVSS 9.8): openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
- CVE-2020-10788 — Critical (CVSS 9.1): openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random…
- CVE-2026-24893 — High (CVSS 8.8): openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition…
- CVE-2023-36663 — High (CVSS 8.8): it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the…
All CVEs affecting It-novum Openitcockpit →
Other CWE-502 (Deserialization of Untrusted Data) vulnerabilities
- CVE-2026-70416 — Critical (CVSS 10.0): Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An…
- CVE-2026-82222 — Critical (CVSS 10.0): Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue…
- CVE-2026-69836 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release…
- CVE-2026-11756 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…
- CVE-2026-41104 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose…
Browse all CWE-502 (Deserialization of Untrusted Data) vulnerabilities →