Checkmk
Checkmk · 108 CVEs
Livestatus injection via monitoring filter values
Sep 22, 2026
Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses
Sep 22, 2026
Missing decompression size limit in agent receiver allows memory exhaustion via push agent data
Sep 21, 2026
Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint
Sep 4, 2026
Missing authorization for viewing background jobs
Aug 25, 2026
Agent receiver accepts mTLS requests without a client certificate
Aug 21, 2026
Frozen BI aggregations leak host and service names to unauthorized users
Aug 20, 2026
Missing Authorization Allows Editing of Foreign Reports
Jul 31, 2026
Fix Business Intelligence API Pack permission
Jul 21, 2026
mk_sap_hana: Privilege escalation via crafted sapstartsrv process name
Jul 14, 2026
Fix XSS in service discovery active check output
Jun 8, 2026
XSS in urls
Jun 8, 2026
Fix stored XSS in global settings change log
Jun 8, 2026
User Messages widget leaked issuer messages on shared dashboards
Jun 8, 2026
Fix stored XSS in URL dashboard widget via dangerous URI schemes
Jun 8, 2026
Privilege escalation via mk_mysql agent plugin on Windows
May 13, 2026
Potential livestatus injection in prediction graph page
Apr 10, 2026
Potential livestatus injection in notification test
Apr 10, 2026
Livestatus injection in monitoring quicksearch
Apr 10, 2026
omd: Local privilege escalation when executing omd commands as root
Apr 7, 2026
Cross-site scripting in dashlet title
Apr 7, 2026
Insufficient permission validation on multiple REST API Quick Setup endpoints
Apr 1, 2026
Stored cross-site scripting in Pending Changes sidebar
Mar 31, 2026
XSS in Unified Search via Unescaped Host/Service Names
Mar 31, 2026
Session hijacking via exposed session signing secret in distributed Checkmk setups
Mar 24, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-90990 | Livestatus injection via monitoring filter values | MEDIUM | 0.42% | Sep 22, 2026 |
| CVE-2026-92882 | Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses | MEDIUM | 0.35% | Sep 22, 2026 |
| CVE-2026-77021 | Missing decompression size limit in agent receiver allows memory exhaustion via push agent data | MEDIUM | 0.38% | Sep 21, 2026 |
| CVE-2026-15937 | Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint | MEDIUM | 0.14% | Sep 4, 2026 |
| CVE-2026-17548 | Missing authorization for viewing background jobs | MEDIUM | 0.21% | Aug 25, 2026 |
| CVE-2026-15576 | Agent receiver accepts mTLS requests without a client certificate | MEDIUM | 0.45% | Aug 21, 2026 |
| CVE-2026-7485 | Frozen BI aggregations leak host and service names to unauthorized users | LOW | 0.35% | Aug 20, 2026 |
| CVE-2026-15227 | Missing Authorization Allows Editing of Foreign Reports | MEDIUM | 0.35% | Jul 31, 2026 |
| CVE-2026-8593 | Fix Business Intelligence API Pack permission | MEDIUM | 0.35% | Jul 21, 2026 |
| CVE-2026-14852 | mk_sap_hana: Privilege escalation via crafted sapstartsrv process name | MEDIUM | 0.18% | Jul 14, 2026 |
| CVE-2026-9549 | Fix XSS in service discovery active check output | MEDIUM | 0.24% | Jun 8, 2026 |
| CVE-2026-8833 | XSS in urls | HIGH | 0.24% | Jun 8, 2026 |
| CVE-2026-8078 | Fix stored XSS in global settings change log | MEDIUM | 0.24% | Jun 8, 2026 |
| CVE-2026-7765 | User Messages widget leaked issuer messages on shared dashboards | MEDIUM | 0.31% | Jun 8, 2026 |
| CVE-2026-7186 | Fix stored XSS in URL dashboard widget via dangerous URI schemes | HIGH | 0.23% | Jun 8, 2026 |
| CVE-2024-47091 | Privilege escalation via mk_mysql agent plugin on Windows | MEDIUM | 0.12% | May 13, 2026 |
| CVE-2026-33457 | Potential livestatus injection in prediction graph page | MEDIUM | 0.29% | Apr 10, 2026 |
| CVE-2026-33456 | Potential livestatus injection in notification test | MEDIUM | 0.34% | Apr 10, 2026 |
| CVE-2026-33455 | Livestatus injection in monitoring quicksearch | MEDIUM | 0.29% | Apr 10, 2026 |
| CVE-2025-39666 | omd: Local privilege escalation when executing omd commands as root | CRITICAL | 0.12% | Apr 7, 2026 |
| CVE-2026-3466 | Cross-site scripting in dashlet title | HIGH | 0.30% | Apr 7, 2026 |
| CVE-2026-24096 | Insufficient permission validation on multiple REST API Quick Setup endpoints | MEDIUM | 0.24% | Apr 1, 2026 |
| CVE-2026-20915 | Stored cross-site scripting in Pending Changes sidebar | HIGH | 0.15% | Mar 31, 2026 |
| CVE-2026-33276 | XSS in Unified Search via Unescaped Host/Service Names | HIGH | 0.23% | Mar 31, 2026 |
| CVE-2025-64998 | Session hijacking via exposed session signing secret in distributed Checkmk setups | HIGH | 0.33% | Mar 24, 2026 |
Showing 1 to 25 of 108 CVEs