5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Description
Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.
Basic Information
ID
CVE-2026-33457
Source
Checkmk
Published
Apr 10, 2026 at 08:31
Modified
Apr 10, 2026 at 12:47
Affected Product
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.5.0
Affected Versions
Checkmk GmbH Checkmk 2.5.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0