CVE-2026-105331
- EPSS -
- Veröffentlicht 08.10.2026 14:19:41
- Zuletzt bearbeitet 08.10.2026 16:17:01
Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.
CVE-2026-90990
- EPSS 0.42%
- Veröffentlicht 22.09.2026 10:43:28
- Zuletzt bearbeitet 22.09.2026 14:17:17
Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queri...
CVE-2026-92882
- EPSS 0.35%
- Veröffentlicht 22.09.2026 10:42:59
- Zuletzt bearbeitet 05.10.2026 15:17:23
Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p38, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP commun...
CVE-2026-77021
- EPSS 0.23%
- Veröffentlicht 21.09.2026 10:57:37
- Zuletzt bearbeitet 21.09.2026 20:17:32
Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small...
CVE-2026-15937
- EPSS 0.14%
- Veröffentlicht 04.09.2026 08:24:49
- Zuletzt bearbeitet 08.09.2026 14:10:24
Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not ve...
CVE-2026-17548
- EPSS 0.21%
- Veröffentlicht 25.08.2026 08:35:17
- Zuletzt bearbeitet 26.08.2026 18:56:51
Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.
CVE-2026-15576
- EPSS 0.27%
- Veröffentlicht 21.08.2026 11:10:00
- Zuletzt bearbeitet 26.08.2026 18:56:51
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulti...
CVE-2026-7485
- EPSS -
- Veröffentlicht 20.08.2026 12:12:52
- Zuletzt bearbeitet 26.08.2026 18:56:51
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services th...
CVE-2026-15227
- EPSS 0.21%
- Veröffentlicht 31.07.2026 12:21:58
- Zuletzt bearbeitet 03.09.2026 04:15:12
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.
CVE-2026-8593
- EPSS 0.21%
- Veröffentlicht 21.07.2026 07:20:35
- Zuletzt bearbeitet 22.07.2026 20:51:36
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules