Home

Description

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page.

PUBLISHED Reserved 2026-05-26 | Published 2026-06-08 | Updated 2026-06-08 | Assigner Checkmk




MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

2.5.0 (semver) before 2.5.0p5
affected

2.4.0 (semver) before 2.4.0p31
affected

2.3.0 (semver) before 2.3.0p48
affected

2.2.0 (semver)
affected

References

checkmk.com/werk/17993 vendor-advisory

cve.org (CVE-2026-9549)

nvd.nist.gov (CVE-2026-9549)

Download JSON