PT-2026-29255 · Checkmk · Checkmk
Michał Kaczmarek
·
Published
2026-03-31
·
Updated
2026-04-02
·
CVE-2026-33276
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions 2.5.0 through 2.5.0b1
Description
A stored cross-site scripting issue exists in Checkmk. An authenticated user with the ability to create hosts or services can inject malicious JavaScript code. This code will then execute in the browsers of other users when they utilize the Unified Search feature. The vulnerability allows for arbitrary JavaScript execution.
Recommendations
Update to version 2.5.0b2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk