Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Checkmk — Vulnerabilities & Security Advisories 99

All 99 CVE vulnerabilities found in Checkmk, with AI-generated Chinese analysis, references, and POCs.

This page provides vulnerability aggregation data for the Checkmk software product, focusing on specific weakness types and security tags relevant to this enterprise monitoring platform. It compiles a comprehensive list of identified security flaws affecting Checkmk systems, covering vulnerability records from the inception of the product’s public release history through the present day. By accessing this resource, users can effectively track vendor advisories as they are issued by the Checkmk development team, gain a deeper understanding of the characteristics and impact of specific weakness classes within the product’s architecture, and review the historical vulnerability timeline to assess the long-term security posture and remediation efforts for each affected version. The information presented is intended to assist security professionals, system administrators, and compliance auditors in maintaining awareness of known security issues and in prioritizing patching and mitigation strategies based on the severity and availability of fixes. All data is organized to facilitate efficient lookup and analysis without requiring manual cross-referencing of multiple external sources. This centralized view helps stakeholders make informed decisions regarding system hardening and risk management. The content strictly adheres to objective reporting standards, ensuring that the information remains factual and useful for technical evaluation purposes. No speculative assessments or subjective rankings are included, allowing for an unbiased review of the security landscape associated with the Checkmk ecosystem.

Vendor: Tribe29

CVE IDTitleCVSSSeverityPublished
CVE-2026-8593 Fix Business Intelligence API Pack permission CWE-862--2026-07-21
CVE-2026-14852 mk_sap_hana: Privilege escalation via crafted sapstartsrv process name CWE-78--2026-07-14
CVE-2026-9549 Fix XSS in service discovery active check output CWE-79--2026-06-08
CVE-2026-8833 XSS in urls CWE-79--2026-06-08
CVE-2026-8078 Fix stored XSS in global settings change log CWE-79--2026-06-08
CVE-2026-7765 User Messages widget leaked issuer messages on shared dashboards CWE-863--2026-06-08
CVE-2026-7186 Fix stored XSS in URL dashboard widget via dangerous URI schemes CWE-79--2026-06-08
CVE-2024-47091 Privilege escalation via mk_mysql agent plugin on Windows CWE-427--2026-05-13
CVE-2026-33457 Potential livestatus injection in prediction graph page CWE-140 8.8 -2026-04-10
CVE-2026-33456 Potential livestatus injection in notification test CWE-140 8.8 -2026-04-10
CVE-2026-33455 Livestatus injection in monitoring quicksearch CWE-140 8.8 -2026-04-10
CVE-2025-39666 omd: Local privilege escalation when executing omd commands as root CWE-426 7.8AIHighAI2026-04-07
CVE-2026-3466 Cross-site scripting in dashlet title CWE-79 5.4AIMediumAI2026-04-07
CVE-2026-24096 Insufficient permission validation on multiple REST API Quick Setup endpoints CWE-280 8.8AIHighAI2026-04-01
CVE-2026-20915 Stored cross-site scripting in Pending Changes sidebar CWE-79 5.4AIMediumAI2026-03-31
CVE-2026-33276 XSS in Unified Search via Unescaped Host/Service Names CWE-79 5.4AIMediumAI2026-03-31
CVE-2025-64998 Session hijacking via exposed session signing secret in distributed Checkmk setups CWE-522 6.5 -2026-03-24
CVE-2026-2859 Unauthenticated Host Enumeration via Observable Response Discrepancy on Deploy Agent Endpoint CWE-204 5.3 -2026-03-13
CVE-2026-24097 Authenticated Host Enumeration via Observable Response Discrepancy on Agent Register Existing Endpoint CWE-204 4.3 -2026-03-13
CVE-2026-3103 Deletion of passwords via RestApi CWE-863 7.1AIHighAI2026-03-04
CVE-2025-64999 Cross-site scripting in HTML logs of Synthetic Monitoring test services CWE-79 6.1AIMediumAI2026-02-26
CVE-2026-24095 Missing Permission Check on Analyze Configuration Page CWE-862 4.3AIMediumAI2026-02-09
CVE-2025-65000 Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule CWE-212 7.5AIHighAI2025-12-18
CVE-2025-64997 Insufficient permission validation when showing agent information CWE-280 6.5AIMediumAI2025-12-18
CVE-2025-58121 Insufficient permission validation on multiple REST API endpoints CWE-280 8.8AIHighAI2025-11-18
CVE-2025-58122 Insufficient permission validation when configuring notification parameters CWE-280 8.1AIHighAI2025-11-18
CVE-2025-64996 Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's output CWE-732 7.1AIHighAI2025-11-18
CVE-2025-39663 Cross Site Scripting through compromised remote site CWE-80 6.1AIMediumAI2025-10-30
CVE-2025-39664 Path-Traversal in report scheduler CWE-22 4.3AIMediumAI2025-10-09
CVE-2025-32919 Privilege Escalation in Windows License plugin for Checkmk Windows Agent CWE-427 7.8AIHighAI2025-10-09

All 99 known CVE vulnerabilities affecting Checkmk with full Chinese analysis, references, and POCs where available.