CVEs we hold for Checkmk
Records whose assigning authority named Checkmk as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9549Fix XSS in service discovery active check outputCheckmk CVE-2026-8593Fix Business Intelligence API Pack permissionCheckmk CVE-2026-7765User Messages widget leaked issuer messages on shared dashboardsCheckmk CVE-2026-7485Frozen BI aggregations leak host and service names to unauthorized usersCheckmk CVE-2026-7186Fix stored XSS in URL dashboard widget via dangerous URI schemesCheckmk CVE-2026-33457Potential livestatus injection in prediction graph pageCheckmk CVE-2026-33456Potential livestatus injection in notification testCheckmk CVE-2026-33276XSS in Unified Search via Unescaped Host/Service NamesCheckmk CVE-2026-2859Unauthenticated Host Enumeration via Observable Response Discrepancy on Deploy Agent EndpointCheckmk CVE-2026-24097Authenticated Host Enumeration via Observable Response Discrepancy on Agent Register Existing EndpointCheckmk CVE-2026-24096Insufficient permission validation on multiple REST API Quick Setup endpointsCheckmk CVE-2026-24095Missing Permission Check on Analyze Configuration PageCheckmk CVE-2026-20915Stored cross-site scripting in Pending Changes sidebarCheckmk CVE-2026-17548Missing authorization for viewing background jobsCheckmk CVE-2026-15937Agent receiver certificate confusion allows authentication with a certificate issued for another endpointCheckmk CVE-2026-15576Agent receiver accepts mTLS requests without a client certificateCheckmk CVE-2026-15227Missing Authorization Allows Editing of Foreign ReportsCheckmk CVE-2026-14852mk_sap_hana: Privilege escalation via crafted sapstartsrv process nameCheckmk CVE-2025-65000Exposure of SSH Private Keys in Remote Alert Handlers (Linux) RuleCheckmk CVE-2025-64999Cross-site scripting in HTML logs of Synthetic Monitoring test servicesCheckmk CVE-2025-64998Session hijacking via exposed session signing secret in distributed Checkmk setupsCheckmk CVE-2025-64997Insufficient permission validation when showing agent informationCheckmk CVE-2025-64996Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's outputCheckmk CVE-2025-58122Insufficient permission validation when configuring notification parametersCheckmk CVE-2025-58121Insufficient permission validation on multiple REST API endpointsCheckmk CVE-2025-39666omd: Local privilege escalation when executing omd commands as rootCheckmk CVE-2025-39663Cross Site Scripting through compromised remote siteCheckmk CVE-2025-3506Potentially senitive path exposed via unauthenticated http routeCheckmk CVE-2025-32919Privilege Escalation in Windows License plugin for Checkmk Windows AgentCheckmk CVE-2025-32915Sensitive data exposed during automatic agent updatesCheckmk CVE-2025-2596Session logout can be overwritten by long lasting requestCheckmk CVE-2025-2092Remote site authentication secrets written to web logCheckmk CVE-2024-6572Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'Checkmk CVE-2024-6163local IP restriction of internal HTTP endpointsCheckmk CVE-2024-47091Privilege escalation via mk_mysql agent plugin on WindowsCheckmk CVE-2024-38860Reflected links in error message facilitate phishing attacksCheckmk CVE-2024-38857Reflected links in visuals facilitate phishing attacksCheckmk CVE-2024-28833Missing brute-force protection for two factor authenticationCheckmk CVE-2024-28826Unrestricted upload and download paths in check_sftpCheckmk CVE-2024-28825Brute-force protection ineffective for some login methodsCheckmk CVE-2024-1742Information disclosure in mk_oracle Checkmk agent pluginCheckmk CVE-2024-13722Checkmk NagVis Reflected Cross-site ScriptingCheckmk NagVis CVE-2023-6156Livestatus injection in availability timelineCheckmk CVE-2023-31211Disabled automation users could still authenticateCheckmk CVE-2023-31210Privilege escalation in agent via LD_LIBRARY_PATHCheckmk CVE-2023-22348Reading host_configs does not honour contact groupsCheckmk 90 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.