PT-2026-29255 · Checkmk · Checkmk

Michał Kaczmarek

·

Published

2026-03-31

·

Updated

2026-04-02

·

CVE-2026-33276

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 2.5.0 through 2.5.0b1
Description A stored cross-site scripting issue exists in Checkmk. An authenticated user with the ability to create hosts or services can inject malicious JavaScript code. This code will then execute in the browsers of other users when they utilize the Unified Search feature. The vulnerability allows for arbitrary JavaScript execution.
Recommendations Update to version 2.5.0b2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33276

Affected Products

Checkmk