Home

Description

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

PUBLISHED Reserved 2025-11-12 | Published 2026-03-24 | Updated 2026-03-25 | Assigner Checkmk




HIGH: 7.3CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-522: Insufficiently Protected Credentials

Product status

Default status
unaffected

2.4.0 (semver) before 2.4.0p23
affected

2.3.0 (semver) before 2.3.0p45
affected

2.2.0 (semver)
affected

Credits

Lisa Gnedt (SBA Research) reporter

References

checkmk.com/werk/18954 vendor-advisory

cve.org (CVE-2025-64998)

nvd.nist.gov (CVE-2025-64998)

Download JSON