Home

Description

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes page or Audit log.

PUBLISHED Reserved 2026-05-07 | Published 2026-06-08 | Updated 2026-06-08 | Assigner Checkmk




MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

2.5.0 (semver) before 2.5.0p5
affected

2.4.0 (semver) before 2.4.0p31
affected

2.3.0 (semver) before 2.3.0p48
affected

2.2.0 (semver)
affected

References

checkmk.com/werk/17992 vendor-advisory

cve.org (CVE-2026-8078)

nvd.nist.gov (CVE-2026-8078)

Download JSON