CVE 8.5 HIGH

Fix stored XSS in URL dashboard widget via dangerous URI schemes_CVE-2026-7186

8.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N

Description

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.

AI Analysis

Stored cross-site scripting vulnerability in Checkmk's URL dashboard widget

Basic Information

ID CVE-2026-7186
Source Checkmk
Published Jun 8, 2026 at 12:05

Affected Product

Vendor Checkmk GmbH
Product Checkmk
Version 2.5.0
Affected Versions Checkmk GmbH Checkmk 2.5.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Checkmk GmbH
Product Checkmk
Version 2.5.0p5, 2.4.0p31, 2.3.0p48, 2.2.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.