- CVE-2026-24893 — Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion
- Added `check_diskstats` plugin to openitcockpit-community-plugins
- EventcorrelationModule: Summary event correlations widget
Full changelog
Changelog - openITCOCKPIT - 5.5.2
Security
- Security: CVE-2026-24893 Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion
Many thanks to @h00die-gr3y for responsibly disclosing these vulnerabilities to us.
Refactoring
- Remove
it-novumfrom openITCOCKPIT Monitoring Agent
New Features
- add
check_diskstatstoopenitcockpit-community-pluginspackage - EventcorrelationModule: Summary event correlations widget
Improvements
- MapModule: Calculate default map height in map widget based on widget height
Bug fixes
- Hosts index: empty pdf and csv lists if regex filter is applied
Blog post: https://openitcockpit.io/blog/posts/2026/2026-04-14-openitcockpit-agent-3.6.0-and-5.5.2/