7.3
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.
Basic Information
ID
CVE-2025-64998
Source
Checkmk
Published
Mar 24, 2026 at 11:25
Modified
Mar 25, 2026 at 03:55
Affected Product
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.4.0
Affected Versions
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0