← Back

Checkmk

checkmk

108 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Checkmk
checkmk

CVEs (108)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Checkmk
1Checkmk
Jun 17, 2026
Dec 18, 2025
6.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.
1Checkmk
1Checkmk
Jun 17, 2026
Nov 18, 2025
4.8 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and...Show more
In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Nov 18, 2025
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosu...Show more
Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Nov 18, 2025
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information
1Checkmk
1Checkmk
Jun 17, 2026
Oct 30, 2025
8.5 HIGH· v4
8.4 HIGH· v3
N/A· v2
Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3...Show more
Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).Show less
1Checkmk
1Checkmk
Jun 17, 2026
Oct 9, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root d...Show more
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Oct 9, 2025
8.8 HIGH· v4
7.8 HIGH· v3
N/A· v2
Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2...Show more
Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL).Show less
1Checkmk
1Checkmk
Jun 17, 2026
Oct 9, 2025
1.0 LOW· v4
4.3 MEDIUM· v3
N/A· v2
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may b...Show more
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web server logs.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Jul 4, 2025
5.3 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Li...Show more
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.Show less
1Checkmk
1Checkmk
Jun 17, 2026
May 22, 2025
4.3 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive...Show more
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.Show less
1Checkmk
1Checkmk
Jun 17, 2026
May 21, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files
1Checkmk
1Checkmk
Jun 17, 2026
May 13, 2025
5.2 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.
1Checkmk
1Checkmk
Jun 17, 2026
May 8, 2025
6.3 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.
1Checkmk
1Checkmk
Jun 17, 2026
Apr 22, 2025
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrat...Show more
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Apr 10, 2025
6.0 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requir...Show more
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Mar 26, 2025
2.3 LOW· v4
5.3 MEDIUM· v3
N/A· v2
Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)
1Checkmk
1Checkmk
Jun 17, 2026
Feb 19, 2025
5.6 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators.
1Checkmk
1Checkmk
Jun 17, 2026
Dec 19, 2024
4.8 MEDIUM· v4
3.3 LOW· v3
N/A· v2
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.
1Checkmk
1Checkmk
Jun 17, 2026
Nov 29, 2024
5.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.
1Checkmk
1Checkmk
Jun 17, 2026
Oct 14, 2024
5.1 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.