Checkmk

Checkmk

120 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 08.10.2026 14:19:41
  • Zuletzt bearbeitet 08.10.2026 16:17:01

Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.

  • EPSS 0.42%
  • Veröffentlicht 22.09.2026 10:43:28
  • Zuletzt bearbeitet 22.09.2026 14:17:17

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queri...

  • EPSS 0.35%
  • Veröffentlicht 22.09.2026 10:42:59
  • Zuletzt bearbeitet 05.10.2026 15:17:23

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p38, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP commun...

  • EPSS 0.23%
  • Veröffentlicht 21.09.2026 10:57:37
  • Zuletzt bearbeitet 21.09.2026 20:17:32

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small...

  • EPSS 0.14%
  • Veröffentlicht 04.09.2026 08:24:49
  • Zuletzt bearbeitet 08.09.2026 14:10:24

Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not ve...

  • EPSS 0.21%
  • Veröffentlicht 25.08.2026 08:35:17
  • Zuletzt bearbeitet 26.08.2026 18:56:51

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

  • EPSS 0.27%
  • Veröffentlicht 21.08.2026 11:10:00
  • Zuletzt bearbeitet 26.08.2026 18:56:51

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulti...

  • EPSS -
  • Veröffentlicht 20.08.2026 12:12:52
  • Zuletzt bearbeitet 26.08.2026 18:56:51

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services th...

  • EPSS 0.21%
  • Veröffentlicht 31.07.2026 12:21:58
  • Zuletzt bearbeitet 03.09.2026 04:15:12

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

  • EPSS 0.21%
  • Veröffentlicht 21.07.2026 07:20:35
  • Zuletzt bearbeitet 22.07.2026 20:51:36

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules