8.5
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
Description
Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.
AI Analysis
Stored cross-site scripting vulnerability in Checkmk's URL dashboard widget
Basic Information
ID
CVE-2026-7186
Source
Checkmk
Published
Jun 8, 2026 at 12:05
Affected Product
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.5.0
Affected Versions
Checkmk GmbH Checkmk 2.5.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.5.0p5, 2.4.0p31, 2.3.0p48, 2.2.0