Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Checkmk — Vulnerabilities & Security Advisories 104

All 104 CVE vulnerabilities found in Checkmk, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Checkmk, a monitoring system developed by Checkmarx (now part of Microsoft), covering a specific class of weaknesses such as cross-site scripting, buffer overflows, and authentication bypass issues. The collection spans the full historical record of publicly disclosed security flaws affecting the product, including both critical and moderate severity advisories released by the vendor over the years. Readers can use this resource to track Checkmk’s security advisories, understand the prevalence of particular weakness types within the product, and review its complete vulnerability history. The data is presented in a structured format, enabling users to filter by year, severity, or weakness category, facilitating trend analysis for security teams and developers. All entries are sourced from official vendor announcements and public bug trackers, ensuring accuracy and consistency. This aggregation serves as a reference point for organizations evaluating the security posture of their monitoring infrastructure, particularly those deploying Checkmk in production environments. The page does not include unverified reports or theoretical risks, focusing instead on confirmed vulnerabilities with documented impact.

Vendor: Tribe29

CVE ID Title CVSS Severity Published
CVE-2026-15937 Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint CWE-295 5.3 Medium 2026-09-04
CVE-2026-17548 Missing authorization for viewing background jobs CWE-862 5.3 Medium 2026-08-25
CVE-2026-15576 Agent receiver accepts mTLS requests without a client certificate CWE-306 6.9 Medium 2026-08-21
CVE-2026-7485 Frozen BI aggregations leak host and service names to unauthorized users CWE-863 2.3 Low 2026-08-20
CVE-2026-15227 Missing Authorization Allows Editing of Foreign Reports CWE-862 5.3 Medium 2026-07-31
CVE-2026-8593 Fix Business Intelligence API Pack permission CWE-862 - - 2026-07-21
CVE-2026-14852 mk_sap_hana: Privilege escalation via crafted sapstartsrv process name CWE-78 5.2 Medium 2026-07-14
CVE-2026-9549 Fix XSS in service discovery active check output CWE-79 - - 2026-06-08
CVE-2026-8833 XSS in urls CWE-79 - - 2026-06-08
CVE-2026-8078 Fix stored XSS in global settings change log CWE-79 - - 2026-06-08
CVE-2026-7765 User Messages widget leaked issuer messages on shared dashboards CWE-863 - - 2026-06-08
CVE-2026-7186 Fix stored XSS in URL dashboard widget via dangerous URI schemes CWE-79 - - 2026-06-08
CVE-2024-47091 Privilege escalation via mk_mysql agent plugin on Windows CWE-427 - - 2026-05-13
CVE-2026-33457 Potential livestatus injection in prediction graph page CWE-140 8.8 - 2026-04-10
CVE-2026-33456 Potential livestatus injection in notification test CWE-140 8.8 - 2026-04-10
CVE-2026-33455 Livestatus injection in monitoring quicksearch CWE-140 8.8 - 2026-04-10
CVE-2025-39666 omd: Local privilege escalation when executing omd commands as root CWE-426 7.8AI High AI 2026-04-07
CVE-2026-3466 Cross-site scripting in dashlet title CWE-79 5.4AI Medium AI 2026-04-07
CVE-2026-24096 Insufficient permission validation on multiple REST API Quick Setup endpoints CWE-280 8.8AI High AI 2026-04-01
CVE-2026-20915 Stored cross-site scripting in Pending Changes sidebar CWE-79 5.4AI Medium AI 2026-03-31
CVE-2026-33276 XSS in Unified Search via Unescaped Host/Service Names CWE-79 5.4AI Medium AI 2026-03-31
CVE-2025-64998 Session hijacking via exposed session signing secret in distributed Checkmk setups CWE-522 6.5 - 2026-03-24
CVE-2026-2859 Unauthenticated Host Enumeration via Observable Response Discrepancy on Deploy Agent Endpoint CWE-204 5.3 - 2026-03-13
CVE-2026-24097 Authenticated Host Enumeration via Observable Response Discrepancy on Agent Register Existing Endpoint CWE-204 4.3 - 2026-03-13
CVE-2026-3103 Deletion of passwords via RestApi CWE-863 7.1AI High AI 2026-03-04
CVE-2025-64999 Cross-site scripting in HTML logs of Synthetic Monitoring test services CWE-79 6.1AI Medium AI 2026-02-26
CVE-2026-24095 Missing Permission Check on Analyze Configuration Page CWE-862 4.3AI Medium AI 2026-02-09
CVE-2025-65000 Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule CWE-212 7.5AI High AI 2025-12-18
CVE-2025-64997 Insufficient permission validation when showing agent information CWE-280 6.5AI Medium AI 2025-12-18
CVE-2025-58121 Insufficient permission validation on multiple REST API endpoints CWE-280 8.8AI High AI 2025-11-18

All 104 known CVE vulnerabilities affecting Checkmk with full Chinese analysis, references, and POCs where available.