PT-2026-21278 · Unknown · Openitcockpit

H00Die-Gr3Y

·

Publicado

2026-02-20

·

Atualizado

2026-02-20

·

CVE-2026-24891

CVSS v3.1

7.5

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openITCOCKPIT versions 5.3.1 and below
Description openITCOCKPIT, an open source monitoring tool, has an unsafe deserialization issue in the Gearman worker implementation. The oitc gearman function uses PHP’s unserialize() on job payloads without proper restrictions or validation. This allows an attacker to potentially trigger PHP Object Injection if they can submit crafted serialized payloads to the Gearman service, especially when Gearman listens on non-local interfaces or network access to TCP/4730 is unrestricted. The issue persists regardless of deployment configuration, as the trust boundary is not enforced in the application code.
Recommendations Upgrade to version 5.4.0 or later.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24891
GHSA-X4MQ-8GFG-FRC4

Produtos afetados

Openitcockpit