Checkmk

Checkmk

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 21.08.2026 11:10:00
  • Zuletzt bearbeitet 21.08.2026 12:16:23

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulti...

  • EPSS -
  • Veröffentlicht 20.08.2026 12:12:52
  • Zuletzt bearbeitet 20.08.2026 13:19:07

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services th...

  • EPSS 0.21%
  • Veröffentlicht 31.07.2026 12:21:58
  • Zuletzt bearbeitet 31.07.2026 20:16:48

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

  • EPSS 0.21%
  • Veröffentlicht 21.07.2026 07:20:35
  • Zuletzt bearbeitet 22.07.2026 20:51:36

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules

  • EPSS 0.22%
  • Veröffentlicht 14.07.2026 09:26:28
  • Zuletzt bearbeitet 29.07.2026 20:17:01

Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA ...

  • EPSS 0.14%
  • Veröffentlicht 08.06.2026 12:07:12
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into c...

  • EPSS 0.14%
  • Veröffentlicht 08.06.2026 12:06:51
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: UR...

  • EPSS 0.14%
  • Veröffentlicht 08.06.2026 12:06:36
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that ex...

  • EPSS 0.19%
  • Veröffentlicht 08.06.2026 12:06:02
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share...

  • EPSS 0.14%
  • Veröffentlicht 08.06.2026 12:05:28
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes sc...